CVE-2026-44317
Description
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-policyauthorization/v1/app-sessions handler panics on a single authenticated request whose ascReqData.suppFeat == "1" (enabling traffic-routing feature negotiation) and whose medComponents entries supply an afAppId but NO AfRoutReq. The create path then calls provisioningOfTrafficRoutingInfo(smPolicy, appID, routeReq, ...) with routeReq == nil and dereferences routeReq.RouteToLocs (and other fields) without a nil check, causing runtime error: invalid memory address or nil pointer dereference. Gin recovery converts the panic into HTTP 500. This vulnerability is fixed in 4.2.2.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | github.com/free5gc/pcf | <1.4.3 | 1.4.3 |
| GO | github.com/free5gc/pcf | < 1.4.3 | 1.4.3 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| free5gc | free5gc | {"endExcluding":"4.2.2"} | 4.2.2 |
References
- https://github.com/free5gc/free5gc/security/advisories/GHSA-wwqh-7jm5-gj7w
- https://github.com/free5gc/free5gc/issues/879
- https://github.com/free5gc/pcf/pull/65
- https://github.com/free5gc/pcf/commit/508d70b8527a6c8c923179dad450ea01e16b6aeb
- https://github.com/free5gc/free5gc
- https://github.com/advisories/GHSA-wwqh-7jm5-gj7w
CWEs
CWE-476 CWE-754
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.