{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/nrf/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-55068"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["free5GC (\u003c 4.2.2)"],"_cs_severities":["critical"],"_cs_tags":["5g-core","free5gc","nrf","cve-2026-55068","input-validation"],"_cs_type":"advisory","_cs_vendors":["free5GC"],"content_html":"\u003cp\u003eThe free5GC Network Repository Function (NRF) exhibits a critical security vulnerability (CVE-2026-55068) in the \u003ccode\u003eRegisterNFInstance\u003c/code\u003e handler, which processes PUT requests at \u003ccode\u003e/nnrf-nfm/v1/nf-instances/{nfInstanceID}\u003c/code\u003e. The NRF accepts NF registration requests without performing input validation against mandatory 3GPP TS 29.510 constraints, including UUID formats, enum values, numeric ranges, and field requirements.\u003c/p\u003e\n\u003cp\u003eThis lack of validation permits unauthenticated attackers to register arbitrary NF profiles, including those with attacker-controlled IP addresses and ports within the \u003ccode\u003eipEndPoints\u003c/code\u003e parameter. Once registered, these malicious profiles are stored in the backend MongoDB and distributed to other network functions via the \u003ccode\u003eNFDiscover\u003c/code\u003e service. This leads to service mesh poisoning, where legitimate network functions like the SMF, AMF, or PCF are tricked into routing control-plane signaling to attacker-controlled endpoints. This vulnerability enables man-in-the-middle interception of sensitive 5G control-plane traffic, OAuth2 credential harvesting, and widespread denial-of-service conditions across the 5G core infrastructure.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains access to the Service-Based Architecture (SBI) network.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious JSON payload mimicking an NF registration request that violates multiple 3GPP constraints.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a PUT request to the NRF endpoint \u003ccode\u003e/nnrf-nfm/v1/nf-instances/\u003c/code\u003e containing the forged \u003ccode\u003enfInstanceId\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe NRF server accepts the invalid request and returns HTTP 201 without validating field integrity.\u003c/li\u003e\n\u003cli\u003eThe NRF stores the fraudulent NF profile in its backend MongoDB collection.\u003c/li\u003e\n\u003cli\u003eA legitimate network function (e.g., SMF) queries the NRF for available NF instances using the \u003ccode\u003eNFDiscover\u003c/code\u003e API.\u003c/li\u003e\n\u003cli\u003eThe NRF returns the malicious profile to the requester in the discovery response.\u003c/li\u003e\n\u003cli\u003eThe legitimate NF selects the attacker-controlled endpoint and attempts to route control-plane signaling to the attacker's server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to compromise the integrity of the entire 5G core service mesh. By redirecting control-plane signaling, an attacker can intercept subscriber traffic, harvest OAuth2 security credentials used for inter-service authentication, and cause systemic denial-of-service for connected subscribers. This vulnerability affects all components of the free5GC suite that rely on the NRF for service discovery, including AMF, SMF, AUSF, UDM, PCF, and NSSF. All versions of free5GC prior to 4.2.2 are vulnerable.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of free5GC to version 4.2.2 or later immediately to apply the patch for CVE-2026-55068.\u003c/li\u003e\n\u003cli\u003eImplement a JSON schema validator for the MongoDB \u003ccode\u003eNfProfile\u003c/code\u003e collection to prevent the storage of malformed NF instances.\u003c/li\u003e\n\u003cli\u003eEnable NRF auditing and logging; although logging does not prevent the attack, it provides the necessary telemetry to detect anomalous NF registration attempts.\u003c/li\u003e\n\u003cli\u003eImplement strict ingress filtering and mTLS for the SBI interface to ensure that only authorized Network Functions can interact with the NRF registration endpoint.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect anomalous HTTP PUT registration requests at the NRF interface.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:13:43Z","date_published":"2026-08-28T21:13:43Z","id":"https://feed.craftedsignal.io/briefs/2026-08-free5gc-nrf-poisoning/","summary":"The free5GC Network Repository Function (NRF) fails to validate NF registration requests against 3GPP TS 29.510 standards, allowing unauthenticated attackers to inject fraudulent network function profiles into the 5G core service mesh.","title":"free5GC NRF NF Registration Poisoning via Input Validation Failure","url":"https://feed.craftedsignal.io/briefs/2026-08-free5gc-nrf-poisoning/"}],"language":"en","title":"CraftedSignal Threat Feed - Nrf","version":"https://jsonfeed.org/version/1.1"}