StackRadar

CVE-2025-60633

Medium

Advisory

Published 24 Nov 2025In the index since 13 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
github.com/free5gc/openapigolangv1.0.8, v1.0.9-0.20240730084323-449098e084621.2.210
OSV records
GHSA-3j9f-7w24-pcqg
Also known as
GO-2025-4162

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
free5gcfree5gcVerified publisher0.1.310 of 12See more

free5gc free5gc 0.1.3

10 of the 12 container images this version deploys carry CVE-2025-60633.

Container imageDigestPackageFixed in
free5gc/amf:v3.4.31bc96ff5a2a6
github.com/free5gc/openapi@v1.0.9-0.20240730084323-449098e08462
1.2.2
free5gc/ausf:v3.4.3687ff4daf5da
github.com/free5gc/openapi@v1.0.8
1.2.2
free5gc/chf:v3.4.3e2a4dd98a4ed
github.com/free5gc/openapi@v1.0.9-0.20240730084323-449098e08462
1.2.2
free5gc/nrf:v3.4.399e46b860efb
github.com/free5gc/openapi@v1.0.9-0.20240730084323-449098e08462
1.2.2
free5gc/nssf:v3.4.3dfe8c68c04b4
github.com/free5gc/openapi@v1.0.8
1.2.2
free5gc/pcf:v3.4.3f712e8ecd927
github.com/free5gc/openapi@v1.0.8
1.2.2
free5gc/smf:v3.4.360e38baa4b10
github.com/free5gc/openapi@v1.0.8
1.2.2
free5gc/udm:v3.4.32f68df062a50
github.com/free5gc/openapi@v1.0.8
1.2.2
free5gc/udr:v3.4.3c0783bcdcbdc
github.com/free5gc/openapi@v1.0.8
1.2.2
free5gc/webui:v3.4.39adeb18492cb
github.com/free5gc/openapi@v1.0.9-0.20240730084323-449098e08462
1.2.2

Open the chart page →

10,693
free5gc-amffree5gc-amfVerified publisher0.1.31 of 1See more

free5gc-amf free5gc-amf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-60633.

Container imageDigestPackageFixed in
free5gc/amf:v3.4.31bc96ff5a2a6
github.com/free5gc/openapi@v1.0.9-0.20240730084323-449098e08462
1.2.2

Open the chart page →

902
free5gc-ausffree5gc-ausfVerified publisher0.1.31 of 1See more

free5gc-ausf free5gc-ausf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-60633.

Container imageDigestPackageFixed in
free5gc/ausf:v3.4.3687ff4daf5da
github.com/free5gc/openapi@v1.0.8
1.2.2

Open the chart page →

910
free5gc-chffree5gc-chfVerified publisher0.1.31 of 1See more

free5gc-chf free5gc-chf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-60633.

Container imageDigestPackageFixed in
free5gc/chf:v3.4.3e2a4dd98a4ed
github.com/free5gc/openapi@v1.0.9-0.20240730084323-449098e08462
1.2.2

Open the chart page →

997
free5gc-nrffree5gc-nrfVerified publisher0.1.31 of 1See more

free5gc-nrf free5gc-nrf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-60633.

Container imageDigestPackageFixed in
free5gc/nrf:v3.4.399e46b860efb
github.com/free5gc/openapi@v1.0.9-0.20240730084323-449098e08462
1.2.2

Open the chart page →

919
free5gc-nssffree5gc-nssfVerified publisher0.1.31 of 1See more

free5gc-nssf free5gc-nssf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-60633.

Container imageDigestPackageFixed in
free5gc/nssf:v3.4.3dfe8c68c04b4
github.com/free5gc/openapi@v1.0.8
1.2.2

Open the chart page →

910
free5gc-pcffree5gc-pcfVerified publisher0.1.31 of 1See more

free5gc-pcf free5gc-pcf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-60633.

Container imageDigestPackageFixed in
free5gc/pcf:v3.4.3f712e8ecd927
github.com/free5gc/openapi@v1.0.8
1.2.2

Open the chart page →

903
free5gc-smffree5gc-smfVerified publisher0.1.31 of 1See more

free5gc-smf free5gc-smf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-60633.

Container imageDigestPackageFixed in
free5gc/smf:v3.4.360e38baa4b10
github.com/free5gc/openapi@v1.0.8
1.2.2

Open the chart page →

918
free5gc-udmfree5gc-udmVerified publisher0.1.31 of 1See more

free5gc-udm free5gc-udm 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-60633.

Container imageDigestPackageFixed in
free5gc/udm:v3.4.32f68df062a50
github.com/free5gc/openapi@v1.0.8
1.2.2

Open the chart page →

910
free5gc-udrfree5gc-udrVerified publisher0.1.31 of 1See more

free5gc-udr free5gc-udr 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-60633.

Container imageDigestPackageFixed in
free5gc/udr:v3.4.3c0783bcdcbdc
github.com/free5gc/openapi@v1.0.8
1.2.2

Open the chart page →

919
free5gc-webuifree5gc-webuiVerified publisher0.1.31 of 1See more

free5gc-webui free5gc-webui 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-60633.

Container imageDigestPackageFixed in
free5gc/webui:v3.4.39adeb18492cb
github.com/free5gc/openapi@v1.0.9-0.20240730084323-449098e08462
1.2.2

Open the chart page →

1,249

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
free5gc/amf:v3.4.31bc96ff5a2a6
github.com/free5gc/openapi@v1.0.9-0.20240730084323-449098e08462
1.2.2
2
free5gc/ausf:v3.4.3687ff4daf5da
github.com/free5gc/openapi@v1.0.8
1.2.2
2
free5gc/chf:v3.4.3e2a4dd98a4ed
github.com/free5gc/openapi@v1.0.9-0.20240730084323-449098e08462
1.2.2
2
free5gc/nrf:v3.4.399e46b860efb
github.com/free5gc/openapi@v1.0.9-0.20240730084323-449098e08462
1.2.2
2
free5gc/nssf:v3.4.3dfe8c68c04b4
github.com/free5gc/openapi@v1.0.8
1.2.2
2
free5gc/pcf:v3.4.3f712e8ecd927
github.com/free5gc/openapi@v1.0.8
1.2.2
2
free5gc/smf:v3.4.360e38baa4b10
github.com/free5gc/openapi@v1.0.8
1.2.2
2
free5gc/udm:v3.4.32f68df062a50
github.com/free5gc/openapi@v1.0.8
1.2.2
2
free5gc/udr:v3.4.3c0783bcdcbdc
github.com/free5gc/openapi@v1.0.8
1.2.2
2
free5gc/webui:v3.4.39adeb18492cb
github.com/free5gc/openapi@v1.0.9-0.20240730084323-449098e08462
1.2.2
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.