Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/mosaic5g/flexric

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-37230: n/aCVE-2026-37230
0

FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in its registry. The lookup returns NULL, triggering assert() in Debug builds (SIGABRT) or NULL pointer dereference in Release builds (SIGSEGV). A remote unauthenticated attacker can crash the near-RT RIC (port 36421) by sending a crafted RIC_INDICATION with an arbitrary ran_func_id value.

Join the discussion
CVE-2026-37229: n/aCVE-2026-37229
0

FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote unauthenticated attacker can send any non-PER byte sequence (e.g., a single 0x00 byte) over SCTP to the near-RT RIC (port 36421) or iApp (port 36422) to crash the process via SIGABRT. The assertion is reached before any protocol-level validation occurs. All three E2AP protocol versions (v1.01, v2.03, v3.01) are affected.

Join the discussion
CVE-2026-37228: n/aCVE-2026-37228
0

FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed 32KB receive buffer and enforces assert(rc < len) on the sctp_recvmsg() return value. A remote unauthenticated attacker can send a single SCTP message with payload >= 32,768 bytes to crash the near-RT RIC, iApp, E2 Agent, or xApp process via SIGABRT. No valid E2AP PDU is required. All four SCTP endpoint types (ports 36421 and 36422) share this vulnerable code path. In Release builds (NDEBUG), the stripped assertion leads to a signed-to-unsigned integer overflow and potential out-of-bounds read.

Join the discussion
CVE-2026-37227: n/aCVE-2026-37227
0

FlexRIC v2.0.0 has a vulnerability where certain whitelisted but unimplemented E2AP message types cause the near-RT RIC process to crash due to reachable assert(0) calls. A remote unauthenticated attacker can exploit this by sending a specially crafted E2AP PDU, such as E2nodeConfigurationUpdate, to trigger a SIGABRT and cause a denial of service. The vulnerability does not impact confidentiality or integrity but results in high availability impact. No patch or official remediation guidance is currently available.

Join the discussion
CVE-2026-37225: n/aCVE-2026-37225
0

CVE-2026-37225 is a vulnerability in FlexRIC v2.0.0 where the iApp process crashes when it receives an E42_RIC_SUBSCRIPTION_REQUEST containing an empty ricEventTriggerDefinition field. This occurs due to a mismatch in validation between the E42 layer decoder, which accepts the empty field as valid, and the E2AP encoder, which requires it to be non-empty. A remote unauthenticated attacker can exploit this to cause a denial of service by crashing the iApp process via SIGABRT. The vulnerability has a high severity with a CVSS score of 7.5 and is categorized under CWE-617 (Reachable Assertion). No patch or official remediation guidance is currently available.

Join the discussion
CVE-2026-37224: n/aCVE-2026-37224
0

FlexRIC v2.0.0 contains a vulnerability where the iApp process crashes upon receiving duplicate E2_SETUP_REQUEST messages from the same or spoofed E2 Node. This occurs because the node ID uniqueness is enforced using assert() instead of graceful rejection, leading to a process abort (SIGABRT). The vulnerability can be triggered remotely by an unauthenticated attacker sending two identical setup requests, causing a denial of service.

Join the discussion
CVE-2026-37223: n/aCVE-2026-37223
0

FlexRIC v2.0.0 has a vulnerability in its iApp message dispatcher where an assertion validates incoming E2AP messages against a fixed whitelist. A remote unauthenticated attacker can send a crafted E2AP message with a type not in the whitelist, causing the iApp process to crash via SIGABRT. This crash terminates the entire near-RT RIC service, disconnecting all E2 Nodes and xApps. The vulnerability has a high severity with a CVSS score of 7.5. No patch or official remediation guidance is currently available.

Join the discussion
CVE-2026-37222: n/aCVE-2026-37222
0

FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. A remote unauthenticated attacker can send a valid E2AP PDU containing an unexpected number of IEs (e.g., an E2setupRequest with extra optional fields) to crash the near-RT RIC (port 36421) or iApp (port 36422) via SIGABRT. The code asserts exact IE counts rather than validating against protocol-specified ranges.

Join the discussion
CVE-2026-37220: n/aCVE-2026-37220
0

FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The near-RT RIC assumes a mapping between SCTP association and E2 node always exists in the cleanup path and enforces this via assert(). A remote unauthenticated attacker can crash the near-RT RIC (port 36421) by simply completing an SCTP handshake and immediately disconnecting, without sending any E2AP message.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:github/mosaic5g/flexric
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses