CVE-2025-60638 Details
Description
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAvailability API.
A denial-of-service vulnerability has been identified in the Free5GC 5G core network implementation, specifically in versions 4.0.0 and 4.0.1. The issue arises within the NSSF component when a crafted POST request is sent to the Nnssf_NSSAIAvailability API without including the optional expiry field. Although the OpenAPI specification correctly designates this field as optional, the server-side implementation mistakenly assumes its presence. This oversight leads to a nil pointer dereference, causing a server-side panic and a 500 Internal Server Error response.
Users can update to Free5GC version 4.1.0, where this issue has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/free5gc/free5gc | [email protected] | Product |
| https://github.com/free5gc/free5gc/issues/704 | [email protected] | ExploitIssue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| free5gc free5gc | 4.0.0 4.0.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 1, 2025 | Initial Analysis | [email protected] |
| Nov 24, 2025 | CVE Modified | CISA-ADP |
| Nov 24, 2025 | New CVE Received | [email protected] |