CVE-2026-1974
Free5GC SMF datapath.go ResolveNodeIdToIp denial of service
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is recommended to apply a patch to fix this issue.
| CWE | CWE-404 |
| Vendor | n/a |
| Product | free5gc |
| Published | Feb 6, 2026 |
| Last Updated | Feb 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a free5gc
Be the first to know when new medium vulnerabilities affecting n/a free5gc are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / Free5GC
4.0 4.1.0
References
vuldb.com: https://vuldb.com/?id.344496 vuldb.com: https://vuldb.com/?ctiid.344496 vuldb.com: https://vuldb.com/?submit.743237 github.com: https://github.com/free5gc/free5gc/issues/816 github.com: https://github.com/free5gc/free5gc/issues/816#issue-3832055233 github.com: https://github.com/free5gc/smf/pull/189 github.com: https://github.com/free5gc/free5gc/
Credits
๐ ZiyuLin (VulDB User)