go package report

Is github.com/free5gc/smf safe?

3 known vulnerabilities, worst severity CRITICAL.

cvss
10.0

how bad it is if exploited, out of 10

epss
0.30%

chance of exploitation in the next 30 days

xyz score
4.0

CyberXYZ composite, out of 10

fig. 01 — GHSA-3258-qmv8-frp3, the advisory selected below

// advisories

GHSA-3258-qmv8-frp3

CRITICALCVE-2026-44329

free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization middleware. A network attacker who can reach SMF on the SBI can hit UPI endpoints with no Authorization header at all, and the requests reach the SMF business handlers. In the running Docker lab this was directly demonstrated for read (GET /upi/v1/upNodesLinks), write (POST /upi/v1/upNodesLinks with attac

Affected
>=0, <1.4.3, < 1.4.3
Fixed in
1.4.3
Weakness
CWE-306
Published
2026-05-08
Source
osv

NVDMITREOSV


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


Checked 2026-09-22 at 02:35 UTC. The most recent advisory here was published 2026-05-08. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is github.com/free5gc/smf safe? go package security report | CyberXYZ