THREAT OPS › Threat News › [GHSA] GHSA-x8mj-6p3q-g5pp (critical) — free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
[GHSA] GHSA-x8mj-6p3q-g5pp (critical) — free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
GHSA-x8mj-6p3q-g5pp Severity: critical CVE: CVE-2026-55068
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
### Summary
free5GC NRF (Docker image free5gc-fuzz:latest) accepts NF registration requests without validating any field constraints against 3GPP TS 29.510, allowing unauthenticated attackers to inject fake NF prof
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-55068cve
- http://172.24.0.10:8000/nnrf-nfm/v1/nf-instances/11111111-1111-1111-1111-111111111111url
- http://172.24.0.10:8000/nnrf-disc/v1/nf-instances?target-nf-type=AMF&requester-nf-type=SMFurl
- http://172.24.0.10:8000/nnrf-nfm/v1/nf-instances/not-a-uuidurl
- 6.1.6.2ipv4
- 5.2.2.2ipv4
- 172.24.0.0/24cidr
Original source: https://github.com/advisories/GHSA-x8mj-6p3q-g5pp