GO · JANUARY 2026 · EARLY WARNING

Potential Scope Validation Bypass in Free5gc NRF 1.4.0

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-Q7C8-GFJH-8V4PSeverity: HIGH

An issue has been reported in Free5gc NRF 1.4.0 that appears to allow attackers to bypass scope validation using a maliciously crafted targetNF value. This could potentially allow attackers to obtain an access token with arbitrary scope.

What happened

According to the GitHub Advisory Database, Free5gc NRF 1.4.0 is under investigation for a vulnerability in the AccessTokenScopeCheck() function. This function reportedly bypasses all scope validation when a crafted targetNF value is used, potentially allowing attackers to obtain an access token with any arbitrary scope.

The affected component is free5gc/nrf (go) version 1.4.0. It is recommended that users upgrade to a version that includes a fix for this issue, or apply a patch if available. The primary source should be consulted for the most up-to-date information and recommended actions.

This issue is currently under investigation and has not been confirmed. No accusations of wrongdoing have been established. Users should monitor updates from the primary source and take appropriate actions to mitigate potential risks.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If free5gc/nrf is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats