github.com/free5gc/pcf
Activity
- Latest release
- 3mo ago
- Total releases
- 18
- Cadence
- ~2 months
- Last 12 months
- 5
Reach
- Stars
- —
Details
- First release
- Jan 18, 2021
| Version | Released | |
|---|---|---|
v1.4.5
patch
|
v1.4.5
patch
Dependencies (15)
+ 7 more |
|
v1.4.4
patch
|
v1.4.4
patch
Dependencies (15)
+ 7 more |
|
v1.4.3
patch
|
v1.4.3
patch
Dependencies (15)
+ 7 more |
|
v1.4.2
patch
3 CVEs
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.4.2
patch
Dependencies (15)
+ 7 more |
|
v1.4.1
patch
4 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (15)
+ 7 more |
|
v1.4.0
minor
4 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (15)
+ 7 more |
|
v1.3.2
patch
5 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60632
GO-2025-4164
GHSA-vgq7-9r5r-j9v3
Dec 02, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.2
patch
Dependencies (14)
+ 6 more |
|
v1.3.1
patch
5 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60632
GO-2025-4164
GHSA-vgq7-9r5r-j9v3
Dec 02, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.1
patch
Dependencies (14)
+ 6 more |
|
v1.2.7
patch
5 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60632
GO-2025-4164
GHSA-vgq7-9r5r-j9v3
Dec 02, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.7
patch
Dependencies (15)
+ 7 more |
|
v1.2.6
patch
5 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60632
GO-2025-4164
GHSA-vgq7-9r5r-j9v3
Dec 02, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.6
patch
Dependencies (15)
+ 7 more |
|
v1.2.5
patch
5 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60632
GO-2025-4164
GHSA-vgq7-9r5r-j9v3
Dec 02, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.5
patch
Dependencies (15)
+ 7 more |
|
v1.2.4
patch
5 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60632
GO-2025-4164
GHSA-vgq7-9r5r-j9v3
Dec 02, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.4
patch
Dependencies (14)
+ 6 more |
|
v1.2.3
patch
5 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60632
GO-2025-4164
GHSA-vgq7-9r5r-j9v3
Dec 02, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.3
patch
Dependencies (14)
+ 6 more |
|
v1.2.2
patch
5 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60632
GO-2025-4164
GHSA-vgq7-9r5r-j9v3
Dec 02, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.2
patch
Dependencies (14)
+ 6 more |
|
v1.2.1
minor
5 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60632
GO-2025-4164
GHSA-vgq7-9r5r-j9v3
Dec 02, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.1
minor
Dependencies (14)
+ 6 more |
|
v1.1.1
minor
5 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60632
GO-2025-4164
GHSA-vgq7-9r5r-j9v3
Dec 02, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.1
minor
Dependencies (15)
+ 7 more |
|
v1.0.2
initial
5 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60632
GO-2025-4164
GHSA-vgq7-9r5r-j9v3
Dec 02, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.2
initial
Dependencies (21)
+ 13 more |
|
v1.3.0
minor
5 CVEs
CVE-2026-44316
GO-2026-5720
GHSA-wr8j-6chw-gm6p
Jun 25, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44317
GO-2026-5731
GHSA-wwqh-7jm5-gj7w
Jun 25, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-41135
GO-2026-5278
GHSA-98cp-84m9-q3qp
Jun 25, 2026
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42083
GO-2026-5189
GHSA-6rgm-gr97-x3j5
Jun 25, 2026
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI in github.com/free5gc/pcf Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60632
GO-2025-4164
GHSA-vgq7-9r5r-j9v3
Dec 02, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.0
minor
Dependencies (21)
+ 13 more |