Free5GC AMF is vulnerable to DoS through its HandleRegistrationComplete function
Moderate severity
GitHub Reviewed
Published
Mar 22, 2026
to the GitHub Advisory Database
•
Updated Apr 6, 2026
Package
Affected versions
< 1.4.3-0.20260306074636-52e9386401ce
Patched versions
1.4.3-0.20260306074636-52e9386401ce
Description
Published by the National Vulnerability Database
Mar 22, 2026
Published to the GitHub Advisory Database
Mar 22, 2026
Reviewed
Mar 24, 2026
Last updated
Apr 6, 2026
A weakness has been identified in Free5GC 4.1.0. Affected is the function HandleRegistrationComplete of the file internal/gmm/handler.go of the component AMF. Executing a manipulation can lead to denial of service. The attack may be performed from remote. This patch is called 52e9386401ce56ea773c5aa587d4cdf7d53da799. It is best practice to apply a patch to resolve this issue.
References