CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-53551

CVE-2026-53551: Improper Input Validation in free5GC Authentication Server Function (AUSF)

Alon Barad
Alon Barad
Software Engineer

Jul 31, 2026·5 min read·12 visits

Executive Summary (TL;DR)

A null-byte input validation bug in free5GC AUSF crashes the authentication flow, causing Denial of Service for connecting subscribers.

Improper input validation of the supiOrSuci field in free5GC Authentication Server Function (AUSF) allows unauthenticated remote attackers to trigger an unhandled parsing exception, resulting in a Denial of Service (DoS) and internal stack trace exposure.

Vulnerability Overview

The Authentication Server Function (AUSF) of free5GC, an open-source 5G core network implementation, is vulnerable to improper input validation in its Service Based Interface (SBI) endpoint. Prior to version 1.4.5 of the AUSF component, the service accepts user-supplied string fields without verification or sanitization.

This lack of validation exposes a critical attack surface on the HTTP/2 API endpoint /nausf-auth/v1/ue-authentications. An unauthenticated remote attacker can supply malformed requests targeting the subscription identifiers, which propagates downstream to internal network functions.

The vulnerability manifests when the AUSF processes the supiOrSuci key in the request payload. By sending control characters inside this field, the attacker forces an unhandled exception inside the Go standard library, culminating in service unavailability.

Root Cause Analysis

The root cause of this vulnerability lies in the improper handling of string variables inside the UeAuthPostRequestProcedure function in internal/sbi/processor/ue_authentication.go. The Go programming language standard library encoding/json decodes incoming JSON payloads without rejecting or escaping embedded control characters, including null bytes (\x00).

When a client submits an authentication request containing raw null bytes in the supiOrSuci parameter, the JSON unmarshaler deserializes the malformed string. The AUSF then uses this parameter to construct an outbound HTTP request aimed at the Unified Data Management (UDM) network function.

The dynamic URL string generation process appends the unvalidated supiOrSuci value directly into the URL path segment. When the constructed URL is passed to Go's net/url.Parse() function for validation prior to execution, the parsing routine detects RFC 3986 compliance violations.

Because the URL contains control characters, the Parse() function returns a syntax error. The AUSF fails to handle this specific error condition gracefully, resulting in an unhandled exception that propagates back as an HTTP 500 Internal Server Error and leaks stack trace data.

Code Analysis

An inspection of the vulnerable codebase in internal/sbi/processor/ue_authentication.go reveals that the supiOrSuci variable was retrieved and directly formatted into the UDM destination URL string.

// Vulnerable Code Path
func (p *Processor) UeAuthPostRequestProcedure(c *gin.Context, updateAuthenticationInfo models.UpdateAuthenticationInfo) {
    ...
    supiOrSuci := updateAuthenticationInfo.SupiOrSuci
    // The value of supiOrSuci is immediately utilized without any format checks
    snName := updateAuthenticationInfo.ServingNetworkName
    ...
    udmURL := fmt.Sprintf("http://%s/nudm-ueau/v1/%s/security-information/...", udmAddr, supiOrSuci)
    // Go's net/url.Parse evaluates udmURL here, resulting in an unhandled parsing error
}

The patch introduced in commit bfc4a10094dbacbd862baa4686829f3fcc06ce1e inserts two validator functions to sanitize the incoming identifier.

// Patched Code Path
func (p *Processor) UeAuthPostRequestProcedure(c *gin.Context, updateAuthenticationInfo models.UpdateAuthenticationInfo) {
    ...
    supiOrSuci := updateAuthenticationInfo.SupiOrSuci
    // Added validation block to catch malformed inputs
    if !validator.IsValidSupi(supiOrSuci) && !validator.IsValidSuci(supiOrSuci) {
        logger.UeAuthLog.Warnf("invalid supiOrSuci in UE authentication request: %q", supiOrSuci)
        problemDetails := models.ProblemDetails{
            Title:  "Malformed request syntax",
            Status: http.StatusBadRequest,
            Detail: "supiOrSuci must be a valid SUPI or SUCI",
            Cause:  "MALFORMED_SUPI_OR_SUCI",
        }
        c.Set(sbi.IN_PB_DETAILS_CTX_STR, problemDetails.Cause)
        c.JSON(http.StatusBadRequest, problemDetails)
        return
    }
    snName := updateAuthenticationInfo.ServingNetworkName
    ...
}

This validator check ensures that the input conforms strictly to the structural rules of Subscriber Permanent Identifiers (SUPI) and Subscription Concealed Identifiers (SUCI). Any input containing non-conforming characters or control bytes is safely rejected before reaching the URL parser.

Exploitation

Exploitation of CVE-2026-53551 does not require prior authentication or specialized network permissions. The attacker needs only network-level access to the Service Based Interface (SBI) endpoint of the AUSF, typically hosted on TCP port 8000.

The attack vector involves sending a single HTTP POST request to /nausf-auth/v1/ue-authentications with a JSON payload where the supiOrSuci field contains null bytes. The structure of the exploit request is illustrated in the following sequence:

By repeatedly issuing this malformed request, an attacker can consume processing threads and memory resources as the service struggles with consecutive unhandled exceptions. This sequence effectively triggers a Denial of Service for all valid core network subscribers attempting to authenticate.

Impact Assessment

The impact of this vulnerability is categorized as a partial Denial of Service on a core network component. Since the AUSF is responsible for processing all user authentication requests, a disruption in this component prevents any new User Equipment (UE) from connecting to the 5G core.

In addition to service disruption, the vulnerability causes information disclosure. The Go runtime logs and returning payloads leak detailed system stack traces and error metadata that can aid attackers in mapping the internal network topology and component versions.

The CVSS v4.0 rating is calculated as 6.9, with a focus on low availability impact on the network service itself. Because free5GC is commonly used in private 5G deployments, enterprise networks, and testbed environments, the threat surface is localized to networks exposing the SBI endpoints.

Remediation & Hardening

The primary remediation path is upgrading the affected software components to versions containing the validation patch. Operators must transition to free5GC version 4.2.2 or higher, which includes AUSF version 1.4.5.

For environments where immediate system upgrades are not possible, operators should deploy an API Gateway or Web Application Firewall (WAF) in front of the AUSF SBI interface. The gateway must be configured to inspect HTTP/2 POST requests targeting /nausf-auth/v1/ue-authentications and discard payloads containing control characters.

Additionally, network segregation should be enforced. The Service Based Interface must be restricted to internal network segments (the 5G Core control plane) and isolated from the public internet or untrusted user-plane segments.

Official Patches

free5gcPR #61: fix: validate supi or suci

Fix Analysis (1)

Technical Appendix

CVSS Score
6.9/ 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Systems

free5gcausf

Affected Versions Detail

Product
Affected Versions
Fixed Version
ausf
free5gc
< 1.4.51.4.5
free5gc
free5gc
< 4.2.24.2.2
AttributeDetail
CWE IDCWE-20
Attack VectorNetwork (Unauthenticated)
CVSS v4.06.9 (Medium)
ImpactDenial of Service (DoS)
Exploit StatusPoC available
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
CWE-20
Improper Input Validation

The product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Known Exploits & Detection

GitHubIssue report detailing reproduction with 5g-fuzzer

Vulnerability Timeline

Vulnerability reported publicly on GitHub issues
2026-05-05
Security patch committed to the repository
2026-05-22
GitHub Security Advisory and CVE-2026-53551 published
2026-07-31

References & Sources

  • [1]GitHub Security Advisory GHSA-qj55-47fp-p62j
  • [2]free5GC GitHub Issue 1048

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•GHSA-W2CH-4XGR-22WW
5.3

GHSA-W2CH-4XGR-22WW: Missing Authorization in Vikunja Task Relation Deletion

An authorization bypass vulnerability in Vikunja versions prior to v2.6.0 permits authenticated users to delete relationships between tasks across project boundaries without requiring read or write authorization for the target related task.

Alon Barad
Alon Barad
1 views•5 min read
•about 2 hours ago•CVE-2026-108258
6.9

CVE-2026-108258: Path Traversal in Shiny for Python Bookmark Restoration

A path traversal vulnerability in Shiny for Python (posit-dev/py-shiny) versions 1.4.0 through 1.6.3 allows unauthenticated remote attackers to read arbitrary files and traverse directories via crafted _state_id_ query parameters.

Alon Barad
Alon Barad
1 views•4 min read
•about 3 hours ago•CVE-2026-108260
7.6

CVE-2026-108260: Stored Cross-Site Scripting (XSS) in @tinacms/web-components

A Stored Cross-Site Scripting vulnerability in @tinacms/web-components prior to version 0.2.1 allows low-privileged content authors to execute arbitrary JavaScript code in the context of website visitors via unsanitized URL attributes in custom Markdown rendering components.

Alon Barad
Alon Barad
3 views•5 min read
•about 4 hours ago•CVE-2026-108261
9.3

CVE-2026-108261: Admin Preview Cross-Origin Bypass and GraphQL Hijacking in TinaCMS

A critical origin validation flaw in TinaCMS admin preview allows unauthenticated attackers to bypass cross-origin postMessage checks and execute unauthorized GraphQL queries and mutations under an authenticated editor's context.

Alon Barad
Alon Barad
5 views•5 min read
•about 5 hours ago•CVE-2026-108259
8.2

CVE-2026-108259: Code Injection in @tinacms/cli via Unsanitized Git Branch Name Interpolation

@tinacms/cli prior to version 3.0.0 dynamically constructs client source files using string interpolation without properly sanitizing runtime configuration variables. An attacker with permissions to create a branch or pull request can inject arbitrary JavaScript statements via a crafted Git ref name, leading to execution during automated build processes.

Amit Schendel
Amit Schendel
8 views•5 min read
•about 6 hours ago•CVE-2026-107804
5.3

CVE-2026-107804: Client IP Resolution Flaw & Authentication Lockout in Nginx UI

Nginx UI versions 2.2.0 through 2.5.10 fail to properly configure Gin framework trusted proxies when deployed behind a reverse proxy. This causes all incoming HTTP requests to be attributed to the loopback IP (127.0.0.1), enabling IP allowlist bypass and global authentication lockouts.

Amit Schendel
Amit Schendel
6 views•5 min read