A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is recommended to apply a patch to fix this issue.
References
| Link | Resource |
|---|---|
| https://github.com/free5gc/free5gc/ | Product |
| https://github.com/free5gc/free5gc/issues/816 | Exploit Issue Tracking Vendor Advisory |
| https://github.com/free5gc/free5gc/issues/816#issue-3832055233 | Exploit Issue Tracking Vendor Advisory |
| https://github.com/free5gc/smf/pull/189 | Issue Tracking |
| https://vuldb.com/?ctiid.344496 | Permissions Required VDB Entry |
| https://vuldb.com/?id.344496 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.743237 | Exploit Third Party Advisory VDB Entry |
Configurations
History
09 Feb 2026, 15:47
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Free5gc free5gc
Free5gc |
|
| CPE | cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:* | |
| References | () https://github.com/free5gc/free5gc/ - Product | |
| References | () https://github.com/free5gc/free5gc/issues/816 - Exploit, Issue Tracking, Vendor Advisory | |
| References | () https://github.com/free5gc/free5gc/issues/816#issue-3832055233 - Exploit, Issue Tracking, Vendor Advisory | |
| References | () https://github.com/free5gc/smf/pull/189 - Issue Tracking | |
| References | () https://vuldb.com/?ctiid.344496 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.344496 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.743237 - Exploit, Third Party Advisory, VDB Entry |
06 Feb 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-06 02:16
Updated : 2026-02-09 15:47
NVD link : CVE-2026-1974
Mitre link : CVE-2026-1974
CVE.ORG link : CVE-2026-1974
JSON object : View
Products Affected
free5gc
- free5gc
CWE
CWE-404
Improper Resource Shutdown or Release
