LIVE · cybersecurity feed
Live wire
vendor

Mosaic5g

8 CVEs published in the last four months. Exploited flaws first.

Critical0
High8
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-372348.2highflexricFlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs.131d ago
CVE-2026-372287.5highflexricFlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c).132d ago
CVE-2026-372297.5highflexricFlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails.132d ago
CVE-2026-372307.5highflexricFlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exi132d ago
CVE-2026-372267.5highflexricFlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node.132d ago
CVE-2026-372337.5highflexricFlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism.132d ago
CVE-2026-372357.5highflexricFlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP associat132d ago
CVE-2026-372317.5highflexricFlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields.132d ago

Filter the full tracker by Mosaic5g →