CVE-2026-4531
Severity CVSS v4.0:
MEDIUM
Type:
CWE-404
Improper Resource Shutdown or Release
Publication date:
22/03/2026
Last modified:
23/03/2026
Description
A weakness has been identified in Free5GC 4.1.0. Affected is the function HandleRegistrationComplete of the file internal/gmm/handler.go of the component AMF. Executing a manipulation can lead to denial of service. The attack may be performed from remote. This patch is called 52e9386401ce56ea773c5aa587d4cdf7d53da799. It is best practice to apply a patch to resolve this issue.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/free5gc/amf/commit/52e9386401ce56ea773c5aa587d4cdf7d53da799
- https://github.com/free5gc/amf/pull/198
- https://github.com/free5gc/free5gc/
- https://github.com/free5gc/free5gc/issues/792
- https://vuldb.com/?ctiid_352319=
- https://vuldb.com/?id_352319=
- https://vuldb.com/?submit_774073=
- https://github.com/free5gc/free5gc/issues/792



