The break is the trust model, not one product. These core stacks treat messages from other network functions as automatically legitimate, so if an internal interface becomes reachable from outside the intended zone, an outsider can interfere with sessions or knock core services offline.
Researchers disclosed 84 flaws across seven open-source LTE and 5G core implementations, including Open5GS, OpenAirInterface, free5GC, SD-Core, eUPF, and XproUPF. The issues span GTP-C and PFCP and can lead to denial of service or session hijacking, with CVE-2026-8233 among the reported flaws.
Cloud-native deployment makes this pattern broader. The same implicit-trust mistake can repeat across different core stacks, so the risk is a reachable interface that was assumed to be internal and safe.