CVE Explorer
CVE-2026-33062
free5GC is an open source 5G core network. free5GC NRF prior to version 1.4.2 has an Improper Input Validation vulnerability leading to Denial of Service. All deployments of free5GC using the NRF discovery service are affected. The `EncodeGroupId` function attempts to access array indices [0], [1], [2] without validating the length of the split data. When the parameter contains insufficient separator characters, the code panics with "index out of range". A remote attacker can cause the NRF servi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"nrf","vendor":"free5gc","versions":[{"status":"affected","version":"< 1.4.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d144dcd4e5f5608c684ae67fa8e9a0e674d786a2807b2758d677b02c068f3119 · sha256:a797a34bf98a8cb2… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d144dcd4e5f5608c684ae67fa8e9a0e674d786a2807b2758d677b02c068f3119 · sha256:a797a34bf98a8cb2… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d144dcd4e5f5608c684ae67fa8e9a0e674d786a2807b2758d677b02c068f3119 · sha256:a797a34bf98a8cb2… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/free5gc/free5gc/issues/777","tags":["x_refsource_MISC"],"url":"https://github.com/free5gc/free5gc/issues/777"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d144dcd4e5f5608c684ae67fa8e9a0e674d786a2807b2758d677b02c068f3119 · sha256:a797a34bf98a8cb2… · /containers/cna/references/1
{"name":"https://github.com/free5gc/free5gc/security/advisories/GHSA-7c47-xr7q-p6hg","tags":["x_refsource_CONFIRM"],"url":"https://github.com/free5gc/free5gc/security/advisories/GHSA-7c47-xr7q-p6hg"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d144dcd4e5f5608c684ae67fa8e9a0e674d786a2807b2758d677b02c068f3119 · sha256:a797a34bf98a8cb2… · /containers/cna/references/0
{"name":"https://github.com/free5gc/nrf/commit/dac77d8f8f2e0f041c5634fb3c685dcb9734b872","tags":["x_refsource_MISC"],"url":"https://github.com/free5gc/nrf/commit/dac77d8f8f2e0f041c5634fb3c685dcb9734b872"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d144dcd4e5f5608c684ae67fa8e9a0e674d786a2807b2758d677b02c068f3119 · sha256:a797a34bf98a8cb2… · /containers/cna/references/3
{"name":"https://github.com/free5gc/nrf/pull/80","tags":["x_refsource_MISC"],"url":"https://github.com/free5gc/nrf/pull/80"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d144dcd4e5f5608c684ae67fa8e9a0e674d786a2807b2758d677b02c068f3119 · sha256:a797a34bf98a8cb2… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.