๐Ÿ” CVE Alert

CVE-2026-53551

UNKNOWN 0.0

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication Server Function) does not validate the supiOrSuci field in UE authentication requests. Null bytes (\x00) and other control characters pass through JSON parsing unchanged and are forwarded to the UDM in an unescaped URL path. This causes Go's net/url.Parse() to fail, returning HTTP 500 "System failure" and leaking internal stack traces. An unauthenticated attacker can trigger this at scale causing denial of service for all subscribers attempting authentication through the affected AUSF. This vulnerability is fixed in 1.4.5.

CWE CWE-20
Vendor free5gc
Product free5gc
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for free5gc free5gc

Be the first to know when new unknown vulnerabilities affecting free5gc free5gc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

free5gc / free5gc
< 4.2.2
free5gc / ausf
< 1.4.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/free5gc/free5gc/security/advisories/GHSA-qj55-47fp-p62j github.com: https://github.com/free5gc/free5gc/issues/1048 github.com: https://github.com/free5gc/ausf/pull/61 github.com: https://github.com/free5gc/ausf/commit/bfc4a10094dbacbd862baa4686829f3fcc06ce1e github.com: https://github.com/free5gc/ausf/releases/tag/v1.4.5 github.com: https://github.com/free5gc/free5gc/releases/tag/v4.2.2