THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fp46-6vfw-gc9c (low) — free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA

[GHSA] GHSA-fp46-6vfw-gc9c (low) — free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA

medgithub_advisoriesPublished 2026-08-28

GHSA-fp46-6vfw-gc9c Severity: low CVE: CVE-2026-55785

free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA

### Summary

The AUSF component of free5GC compares authentication response values with normal Go equality helpers instead of constant-time cryptographic comparison functions.

Two authentication flows are affected in `internal/sbi/processor/ue_authenticat

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fp46-6vfw-gc9c