ZeroHour

CVE-2026-30067

niche

Unauthenticated DoS in free5GC v4.0.1 NRF Discovery Service

CVSS 3.1
7.5 high
EPSS
<1%p37
Published
()
Modified
AI analysis

free5GC v4.0.1 contains a denial-of-service flaw (CWE-770, allocation of resources without limits or throttling) in the complexQueryFilterSubprocess function of the NRF Discovery service. A remote, unauthenticated attacker can trigger it by sending crafted input to the network repository function's discovery interface, consistent with resource exhaustion on the affected service. Because the NRF handles service discovery and registration for 5G core network functions, a successful attack degrades availability of the 5G core and can disrupt dependent network services, with no confidentiality or integrity impact per the CVSS scoring. Organizations running free5GC v4.0.1 — typically research testbeds, academic labs, and private 5G network trials rather than mass-market carrier deployments — are affected. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.4%.

What to do: Organizations running free5GC v4.0.1 should track the free5GC project for a patched release and upgrade the NRF component promptly once a fix is published. In the interim, restrict network access to the NRF discovery interface to trusted management and 5G core networks, and monitor the NRF service for abnormal resource consumption or availability drops.

Affected
free5GC NRF Discovery servicev4.0.1 (the only version listed in the advisory; affected/fixed ranges not specified in the available data)
Estimated exposure
nichehundreds to low thousands of deployments, most of them non-internet-facing (research testbeds and private 5G trials) — free5GC is a widely used open-source 5G core whose adoption is concentrated in academic, research, and private-network trial deployments that typically run the NRF inside protected core network segments rather than exposed to the internet,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.