THREAT OPS › Threat News › [GHSA] GHSA-334q-h5g3-fpxv (high) — free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
[GHSA] GHSA-334q-h5g3-fpxv (high) — free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
GHSA-334q-h5g3-fpxv Severity: high CVE: CVE-2026-55784
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
### Summary
The AUSF component of free5GC stores per-subscriber authentication state in a global `sync.Map` keyed only by SUPI. Every incoming authentication request creates a new `AusfUeContext` and stores it under that SUPI key without checkin
Indicators of compromise
- CVE-2026-55784cve
- CVE-2026-33063cve
- CVE-2026-44318cve
Original source: https://github.com/advisories/GHSA-334q-h5g3-fpxv