๐Ÿ” CVE Alert

CVE-2026-32937

UNKNOWN 0.0

free5GC CHF has Out-of-Bounds Slice Access that Leads to DoS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
13th

free5GC is an open source 5G core network. free5GC CHF prior to version 1.2.2 has an out-of-bounds slice access vulnerability in the CHF `nchf-convergedcharging` service. A valid authenticated request to PUT `/nchf-convergedcharging/v3/recharging/:ueId?ratingGroup=...` can trigger a server-side panic in `github.com/free5gc/chf/internal/sbi.(*Server).RechargePut(...)` due to an out-of-range slice access. In the reported runtime, Gin recovery converts the panic into HTTP 500, but the recharge path remains remotely panic-triggerable and can be abused repeatedly to degrade recharge functionality and flood logs. In deployments without equivalent recovery handling, this panic may cause more severe service disruption. free5GC CHF patches the issue. Some workarounds are available: Restrict access to the `nchf-convergedcharging` recharge endpoint to strictly trusted NF callers only; apply rate limiting or network ACLs in front of the CHF SBI interface to reduce repeated panic-trigger attempts; if the recharge API is not required, temporarily disable or block external reachability to this route; and/or ensure panic recovery, monitoring, and alerting are enabled.

CWE CWE-129
Vendor free5gc
Product chf
Published Mar 20, 2026
Last Updated Mar 20, 2026
Stay Ahead of the Next One

Get instant alerts for free5gc chf

Be the first to know when new unknown vulnerabilities affecting free5gc chf are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

free5gc / chf
< 1.2.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/free5gc/free5gc/security/advisories/GHSA-6g43-577r-wf4x github.com: https://github.com/free5gc/free5gc/issues/864 github.com: https://github.com/free5gc/chf/pull/61 github.com: https://github.com/free5gc/chf/commit/55af766f321a00afa978e806548c96f8a7d2433e