<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 10:38:01 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322454</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322454</link>
      <description>EUVD-2026-322454</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322454</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44327</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44327</link>
      <description>&lt;p&gt;free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC&amp;#39;s NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route with no Authorization header at all and the handler returns 200 OK. The current OAM handler is a stub that returns null, but the structural defect is route-group-scoped: the entire OAM route group has no inbound auth middleware, so every future OAM operation added to this group inherits the missing auth boundary by default. This vulnerability is fixed in 4.2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC&amp;#39;s NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route with no Authorization header at all and the handler returns 200 OK. The current OAM handler is a stub that returns null, but the structural defect is route-group-scoped: the entire OAM route group has no inbound auth middleware, so every future OAM operation added to this group inherits the missing auth boundary by default. This vulnerability is fixed in 4.2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44327</guid>
    </item>
    <item>
      <title>GHSA-cmpj-2x3g-m7g3 — free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cmpj-2x3g-m7g3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/free5gc/nef&lt;/p&gt;
&lt;p&gt;### Summary
free5GC&amp;#39;s NEF mounts the `nnef-oam` route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route with no `Authorization` header at all and the handler returns `200 OK`. The current OAM handler is a stub that returns `null`, but the structural defect is route-group-scoped: the entire OAM route group has no inbound auth middleware, so every future OAM operation added to this group inherits the missing auth boundary by default. Same root cause as the NEF traffic-influence and PFD-management findings.&lt;/p&gt;
&lt;p&gt;### Details
Validated against the NEF container in the official Docker compose lab.
- Source repo tag: `v4.2.1`
- Running Docker image: `free5gc/nef:v4.2.0`
- Runtime NEF commit: `5ce35eab`
- Docker validation date: 2026-03-11&lt;/p&gt;
&lt;p&gt;NEF advertises `OAuth2 setting receive from NRF: true`, yet the OAM route group is mounted without any inbound auth middleware and answers unauthenticated `GET`s with `200 OK`.&lt;/p&gt;
&lt;p&gt;Code evidence (paths in `free5gc/nef`):
- OAM route group mounted without auth middleware: `NFs/nef/internal/sbi/server.go:60`
- OAM route exposed at `/`: `NFs/nef/internal/sbi/api_oam.go:9`
- OAM processor returns `200 OK` directly: `NFs/nef/internal/sbi/processor/oam.go:9`
- NEF context only exposes outbound token acquisition (`GetTokenCtx`); there is no inbound authorization path: `NFs/nef/internal/context/nef_context.go:153`&lt;/p&gt;
&lt;p&gt;### PoC
Reproduced against the running NEF at `http://10.100.200.19:800…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/free5gc/nef&lt;/p&gt;
&lt;p&gt;### Summary
free5GC&amp;#39;s NEF mounts the `nnef-oam` route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route with no `Authorization` header at all and the handler returns `200 OK`. The current OAM handler is a stub that returns `null`, but the structural defect is route-group-scoped: the entire OAM route group has no inbound auth middleware, so every future OAM operation added to this group inherits the missing auth boundary by default. Same root cause as the NEF traffic-influence and PFD-management findings.&lt;/p&gt;
&lt;p&gt;### Details
Validated against the NEF container in the official Docker compose lab.
- Source repo tag: `v4.2.1`
- Running Docker image: `free5gc/nef:v4.2.0`
- Runtime NEF commit: `5ce35eab`
- Docker validation date: 2026-03-11&lt;/p&gt;
&lt;p&gt;NEF advertises `OAuth2 setting receive from NRF: true`, yet the OAM route group is mounted without any inbound auth middleware and answers unauthenticated `GET`s with `200 OK`.&lt;/p&gt;
&lt;p&gt;Code evidence (paths in `free5gc/nef`):
- OAM route group mounted without auth middleware: `NFs/nef/internal/sbi/server.go:60`
- OAM route exposed at `/`: `NFs/nef/internal/sbi/api_oam.go:9`
- OAM processor returns `200 OK` directly: `NFs/nef/internal/sbi/processor/oam.go:9`
- NEF context only exposes outbound token acquisition (`GetTokenCtx`); there is no inbound authorization path: `NFs/nef/internal/context/nef_context.go:153`&lt;/p&gt;
&lt;p&gt;### PoC
Reproduced against the running NEF at `http://10.100.200.19:800…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cmpj-2x3g-m7g3</guid>
    </item>
  </channel>
</rss>
