CVE-2026-30073
nicheUnauthenticated DoS in free5GC v4.0.1 via crafted POST requests
CVE-2026-30073 is a denial-of-service flaw (CWE-770, allocation of resources without limits) in the NssaiAvailabilitySubscriptionCreate component of free5GC v4.0.1, an open-source 5G core network implementation. An unauthenticated remote attacker can trigger it by sending a crafted POST request to the affected component, causing resource exhaustion that disrupts the service. The impact is limited to availability (CVSS A:H, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, 7.5 High), meaning attackers can knock the affected 5G core function offline but cannot read or modify data. Anyone running free5GC v4.0.1, typically operators of research testbeds, labs, and private or emerging 5G deployments, is affected. There is currently no known public proof-of-concept, no CISA KEV listing, and EPSS estimates only a 0.4% probability of exploitation within 30 days.
What to do: Upgrade free5GC to a release newer than v4.0.1 once a patched version is published, and verify your deployed version. Until then, restrict network access to the NssaiAvailabilitySubscriptionCreate endpoint (the affected network function's service interface) to trusted network functions and management networks only, and monitor for unauthenticated or malformed POST requests. Note that the flaw is availability-only, so exposure to data compromise is not expected.
| free5GC (open-source project) free5GC | v4.0.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- Weakness
- CWE-770
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.