CVE-2026-55785 | free5GC up to 1.4.4 AUSF ue_authentication.go timing discrepancy

SecurityVulns

A vulnerability was found in free5GC up to 1.4.4. It has been declared as problematic. Impacted is the function Auth5gAkaComfirmRequestProcedure/EapAuthComfirmRequestProcedure of the file internal/sbi/processor/ue_authentication.go of the component AUSF. Such manipulation leads to observable timing discrepancy.

This vulnerability is uniquely identified as CVE-2026-55785. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More