Free5Gc · Free5Gc · CVE-2026-30068
**Name of the Vulnerable Software and Affected Versions**
free5gc version 4.0.1
**Description**
Improper input validation in the `HandleUpdate()` function located in `/sbi/parameter provision.go` allows attackers to cause a Denial of Service (DoS), a condition where the service becomes unavailable to its intended users, by providing a crafted input.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting access to the `HandleUpdate()` function to minimize the risk of exploitation.