THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qj55-47fp-p62j (medium) — free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure

[GHSA] GHSA-qj55-47fp-p62j (medium) — free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure

highgithub_advisoriesPublished 2026-07-31

GHSA-qj55-47fp-p62j Severity: medium CVE: CVE-2026-53551

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure

### Summary

The free5GC AUSF (Authentication Server Function) does not validate the `supiOrSuci` field in UE authentication requests. Null bytes (`\x00`) and other control characters pass through JSON parsing unchanged and are forwarded to the UDM in

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qj55-47fp-p62j