CVE-2026-42083: Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI
References
- github.com/advisories/GHSA-6rgm-gr97-x3j5
- github.com/free5gc/free5gc
- github.com/free5gc/free5gc/issues/844
- github.com/free5gc/free5gc/security/advisories/GHSA-6rgm-gr97-x3j5
- github.com/free5gc/pcf/commit/8c4d457cdf58bb239ee30e88c56b370b22073964
- github.com/free5gc/pcf/pull/63
- nvd.nist.gov/vuln/detail/CVE-2026-42083
Code Behaviors & Features
Detect and mitigate CVE-2026-42083 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →