A vulnerability has been found in Free5GC up to 4.1.0. This affects an unknown function of the component PFCP UDP Endpoint. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/free5gc/free5gc/ | Product |
| https://github.com/free5gc/free5gc/issues/796 | Exploit Issue Tracking Vendor Advisory |
| https://github.com/free5gc/free5gc/issues/796#issue-3812169865 | Exploit Issue Tracking Vendor Advisory |
| https://vuldb.com/?ctiid.346113 | Permissions Required VDB Entry |
| https://vuldb.com/?id.346113 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.739509 | Third Party Advisory VDB Entry |
Configurations
History
19 Feb 2026, 19:48
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/free5gc/free5gc/ - Product | |
| References | () https://github.com/free5gc/free5gc/issues/796 - Exploit, Issue Tracking, Vendor Advisory | |
| References | () https://github.com/free5gc/free5gc/issues/796#issue-3812169865 - Exploit, Issue Tracking, Vendor Advisory | |
| References | () https://vuldb.com/?ctiid.346113 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.346113 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.739509 - Third Party Advisory, VDB Entry | |
| CPE | cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:* | |
| First Time |
Free5gc free5gc
Free5gc |
18 Feb 2026, 17:52
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
16 Feb 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-16 02:16
Updated : 2026-02-19 19:48
NVD link : CVE-2026-2525
Mitre link : CVE-2026-2525
CVE.ORG link : CVE-2026-2525
JSON object : View
Products Affected
free5gc
- free5gc
CWE
CWE-404
Improper Resource Shutdown or Release
