THREAT OPS › Threat News › [GHSA] GHSA-fp46-6vfw-gc9c (low) — free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
[GHSA] GHSA-fp46-6vfw-gc9c (low) — free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
GHSA-fp46-6vfw-gc9c Severity: low CVE: CVE-2026-55785
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
### Summary
The AUSF component of free5GC compares authentication response values with normal Go equality helpers instead of constant-time cryptographic comparison functions.
Two authentication flows are affected in `internal/sbi/processor/ue_authenticat
Indicators of compromise
- CVE-2026-55785cve
- CVE-2026-33063cve
Original source: https://github.com/advisories/GHSA-fp46-6vfw-gc9c