CVE-2026-1973 | Free5GC up to 4.1.0 SMF establishPfcpSession null pointer dereference (Issue 815 / EUVD-2026-5605)
A vulnerability labeled as problematic has been found in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference.
The identification of this vulnerability is CVE-2026-1973. The attack may be launched remotely. Furthermore, there is an exploit available.
It is best practice to apply a patch to resolve this issue.