<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 11:26:37 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322207</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322207</link>
      <description>EUVD-2026-322207</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322207</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44328</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44328</link>
      <description>&lt;p&gt;free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC&amp;#39;s SMF mounts the UPI management route group without inbound OAuth2 middleware. On top of that, the DELETE /upi/v1/upNodesLinks/{upNodeRef} handler unconditionally dereferences upNode.UPF after the type-guarded async release, even though AN-typed nodes are constructed without a UPF object. As a result, a single unauthenticated DELETE /upi/v1/upNodesLinks/gNB1 request crashes the handler with a nil-pointer panic AND mutates the in-memory user-plane topology before panicking (the UpNodeDelete(upNodeRef) line runs first). This is an unauthenticated, state-mutating panic-DoS sink that an off-path network attacker can trigger by name against any AN entry. This vulnerability is fixed in 4.2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC&amp;#39;s SMF mounts the UPI management route group without inbound OAuth2 middleware. On top of that, the DELETE /upi/v1/upNodesLinks/{upNodeRef} handler unconditionally dereferences upNode.UPF after the type-guarded async release, even though AN-typed nodes are constructed without a UPF object. As a result, a single unauthenticated DELETE /upi/v1/upNodesLinks/gNB1 request crashes the handler with a nil-pointer panic AND mutates the in-memory user-plane topology before panicking (the UpNodeDelete(upNodeRef) line runs first). This is an unauthenticated, state-mutating panic-DoS sink that an off-path network attacker can trigger by name against any AN entry. This vulnerability is fixed in 4.2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44328</guid>
    </item>
    <item>
      <title>GHSA-p9mg-74mg-cwwr — free5GC's SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p9mg-74mg-cwwr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/free5gc/smf&lt;/p&gt;
&lt;p&gt;### Summary
free5GC&amp;#39;s SMF mounts the `UPI` management route group without inbound OAuth2 middleware (same root cause as the broader UPI auth gap reported in free5gc/free5gc#887). On top of that, the `DELETE /upi/v1/upNodesLinks/{upNodeRef}` handler unconditionally dereferences `upNode.UPF` after the type-guarded async release, even though `AN`-typed nodes are constructed without a `UPF` object. As a result, a single unauthenticated `DELETE /upi/v1/upNodesLinks/gNB1` request crashes the handler with a nil-pointer panic AND mutates the in-memory user-plane topology before panicking (the `UpNodeDelete(upNodeRef)` line runs first). This is an unauthenticated, state-mutating panic-DoS sink that an off-path network attacker can trigger by name against any AN entry.&lt;/p&gt;
&lt;p&gt;### Details
Validated against the SMF container in the official Docker compose lab.
- Source repo tag: `v4.2.1`
- Running Docker image: `free5gc/smf:v4.2.1`
- Runtime SMF commit: `8385c00a`
- Docker validation date: 2026-03-22 local (container log timestamp `2026-03-21T23:43:17Z`)
- SMF endpoint: `http://10.100.200.6:8000`&lt;/p&gt;
&lt;p&gt;Control comparison on the same SMF instance:
- `GET /nsmf-oam/v1/` (no token) -&amp;gt; `401 Unauthorized`
- `DELETE /upi/v1/upNodesLinks/gNB1` (no token) -&amp;gt; `500 Internal Server Error` (panic)&lt;/p&gt;
&lt;p&gt;The sibling `nsmf-oam` returning `401` proves OAuth middleware IS wired in for other SMF route groups; the UPI group specifically is mounted without it.&lt;/p&gt;
&lt;p&gt;Vulnerable handler logic (paths in `free5gc/smf`):
```go
//…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/free5gc/smf&lt;/p&gt;
&lt;p&gt;### Summary
free5GC&amp;#39;s SMF mounts the `UPI` management route group without inbound OAuth2 middleware (same root cause as the broader UPI auth gap reported in free5gc/free5gc#887). On top of that, the `DELETE /upi/v1/upNodesLinks/{upNodeRef}` handler unconditionally dereferences `upNode.UPF` after the type-guarded async release, even though `AN`-typed nodes are constructed without a `UPF` object. As a result, a single unauthenticated `DELETE /upi/v1/upNodesLinks/gNB1` request crashes the handler with a nil-pointer panic AND mutates the in-memory user-plane topology before panicking (the `UpNodeDelete(upNodeRef)` line runs first). This is an unauthenticated, state-mutating panic-DoS sink that an off-path network attacker can trigger by name against any AN entry.&lt;/p&gt;
&lt;p&gt;### Details
Validated against the SMF container in the official Docker compose lab.
- Source repo tag: `v4.2.1`
- Running Docker image: `free5gc/smf:v4.2.1`
- Runtime SMF commit: `8385c00a`
- Docker validation date: 2026-03-22 local (container log timestamp `2026-03-21T23:43:17Z`)
- SMF endpoint: `http://10.100.200.6:8000`&lt;/p&gt;
&lt;p&gt;Control comparison on the same SMF instance:
- `GET /nsmf-oam/v1/` (no token) -&amp;gt; `401 Unauthorized`
- `DELETE /upi/v1/upNodesLinks/gNB1` (no token) -&amp;gt; `500 Internal Server Error` (panic)&lt;/p&gt;
&lt;p&gt;The sibling `nsmf-oam` returning `401` proves OAuth middleware IS wired in for other SMF route groups; the UPI group specifically is mounted without it.&lt;/p&gt;
&lt;p&gt;Vulnerable handler logic (paths in `free5gc/smf`):
```go
//…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p9mg-74mg-cwwr</guid>
    </item>
  </channel>
</rss>
