{"id":"GO-2026-6328","summary":"free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA in github.com/free5gc/ausf","details":"free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA in github.com/free5gc/ausf","aliases":["CVE-2026-55785","GHSA-fp46-6vfw-gc9c"],"modified":"2026-09-02T19:45:14.135011150Z","published":"2026-09-02T18:37:27Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-6328","review_status":"UNREVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/free5gc/free5gc/security/advisories/GHSA-fp46-6vfw-gc9c"},{"type":"FIX","url":"https://github.com/free5gc/ausf/commit/7a5a4aa1ec6cd0e1febebf333911c3104968edf0"}],"affected":[{"package":{"name":"github.com/free5gc/ausf","ecosystem":"Go","purl":"pkg:golang/github.com/free5gc/ausf"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.4.5"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6328.json"}}],"schema_version":"1.9.0"}