What is CVE-2026-53551?
CVE-2026-53551 is a vulnerability in the AUSF component of the open-source free5GC 5G core network prior to version 1.4.5. The supiOrSuci field in UE authentication requests is not validated, allowing null bytes and control characters to pass through JSON parsing. It is strongly recommended to upgrade to version 1.4.5 or later to mitigate this issue.
Azərbaycanca: CVE-2026-53551 free5GC açıq mənbəli 5G nüvə şəbəkəsinin AUSF funksiyasında aşkarlanmış boşluqdur. 1.4.5 versiyasından əvvəl, UE autentifikasiya sorğularında supiOrSuci sahəsi düzgün yoxlanılmır və null byte kimi simvollar JSON parsing-dən keçir. Bu problemi aradan qaldırmaq üçün ən qısa zamanda 1.4.5 və ya daha yuxarı versiyaya yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
In which component of free5GC was CVE-2026-53551 discovered?
This vulnerability was discovered in the AUSF component of the open-source free5GC 5G core network.
To which version should free5GC be upgraded to mitigate CVE-2026-53551?
To mitigate this issue, free5GC should be upgraded to version 1.4.5 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.