{"id":"CVE-2026-4531","aliases":["GHSA-xq44-64rg-8g3h","GO-2026-5767"],"url":"https://o3.security/vulnerability/CVE-2026-4531","summary":"Free5GC AMF handler.go HandleRegistrationComplete denial of service","details":"A weakness has been identified in Free5GC 4.1.0. Affected is the function HandleRegistrationComplete of the file internal/gmm/handler.go of the component AMF. Executing a manipulation can lead to denial of service. The attack may be performed from remote. This patch is called 52e9386401ce56ea773c5aa587d4cdf7d53da799. It is best practice to apply a patch to resolve this issue.","published":"2026-03-22T01:32:11.642Z","modified":"2026-09-04T03:31:00.013005461Z","cvss":null,"epss":{"score":0.00427,"percentile":0.35629,"asOf":"2026-08-31"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/free5gc/amf","fixedVersion":"1.4.3-0.20260306074636-52e9386401ce"}],"fix":{"url":"https://github.com/free5gc/amf/commit/52e9386401ce56ea773c5aa587d4cdf7d53da799","label":"free5gc/amf@52e9386"},"references":[{"type":"WEB","url":"https://github.com/free5gc/free5gc/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4531.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4531"},{"type":"ADVISORY","url":"https://vuldb.com/?id.352319"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.774073"},{"type":"REPORT","url":"https://github.com/free5gc/free5gc/issues/792"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.352319"},{"type":"FIX","url":"https://github.com/free5gc/amf/commit/52e9386401ce56ea773c5aa587d4cdf7d53da799"},{"type":"FIX","url":"https://github.com/free5gc/amf/pull/198"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-04T03:31:00.013005461Z"}}