CVE-2026-4531: Free5GC AMF is vulnerable to DoS through its HandleRegistrationComplete function
(updated )
A weakness has been identified in Free5GC 4.1.0. Affected is the function HandleRegistrationComplete of the file internal/gmm/handler.go of the component AMF. Executing a manipulation can lead to denial of service. The attack may be performed from remote. This patch is called 52e9386401ce56ea773c5aa587d4cdf7d53da799. It is best practice to apply a patch to resolve this issue.
References
- github.com/advisories/GHSA-xq44-64rg-8g3h
- github.com/free5gc/amf
- github.com/free5gc/amf/commit/52e9386401ce56ea773c5aa587d4cdf7d53da799
- github.com/free5gc/amf/pull/198
- github.com/free5gc/free5gc/issues/792
- nvd.nist.gov/vuln/detail/CVE-2026-4531
- vuldb.com/?ctiid.352319
- vuldb.com/?id.352319
- vuldb.com/?submit.774073
Code Behaviors & Features
Detect and mitigate CVE-2026-4531 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →