Package impact

golang Go / github.com/free5gc/nef

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2026-44327 critical 10.0 10.0 19h ago free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler golang
CVE-2026-44330 critical 10.0 10.0 19h ago free5GC's NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens can read PFD data and create/delete PFD subscriptions golang
CVE-2026-44315 critical 9.4 9.4 19h ago free5GC's NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, read, and delete PFD transactions golang
CVE-2026-44326 critical 9.4 9.4 19h ago free5GC's NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer tokens can create, read, patch, and delete subscriptions golang
CVE-2026-44319 high 7.5 7.5 19h ago free5GC's NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri) golang
CVE-2026-44322 high 7.5 7.5 19h ago free5GC's NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference golang
CVE-2026-44320 high 7.3 7.3 19h ago free5GC's NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing path golang