CVE-2026-5661 Details
Description
A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handler. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit is publicly available and might be used.
A denial-of-service vulnerability has been identified in Free5GC version 4.2.0, specifically within the NGSetupRequest Handler component. The issue arises when the Criticality field in the NGSetupRequest is set to 'Ignore' for the UERetentionInformation, leading to the generation of two responses—one successful and one failed. This behavior can cause a desynchronization of client state, creating ambiguity about which response should be acknowledged. The vulnerability can be exploited remotely, and a public exploit is available.
A patch for this vulnerability is being developed and can be tracked in the Free5GC AMF repository, where the issue has been acknowledged and addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 6, 2026CISA-ADP
Assessed Apr 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/free5gc/amf/pull/201 | [email protected] | Issue TrackingVendor |
| https://github.com/free5gc/free5gc/ | [email protected] | Vendor |
| https://github.com/free5gc/free5gc/issues/832 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/user-attachments/files/25581199/amfcfg.yaml | [email protected] | Broken Link |
| https://vuldb.com/submit/785896 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://vuldb.com/vuln/355485 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/vuln/355485/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Free5GC | 4.2.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 6, 2026 | New CVE Received | [email protected] |
Volerion