Vulnerabilities
Report: CVE-2026-33062 - free5GC NRF Discovery EncodeGroupId Function Panics on Malformed group-id-list P...
CVE ID :CVE-2026-33062 Published : March 20, 2026, 3:16 a.m. | 36 minutes ago Description :free5GC is an open source 5G core network. free5GC NRF prior to version 1.4.2 has an Improper Input Validation vulnerability leading to Denial of Service. All deployments of free5GC using the NRF discovery service are affected. The `EncodeGroupId` function attempts to access array indices [0], [1], [2] without validating the length of the split data. When the parameter contains insufficient separator characters, the code panics with
CVE Details
CVE ID
Published
March 20, 2026
Attack Vector:
network
Impact:
Denial of Service