Critical Advisory: HTTP/2 NRF Authorization Flaws in 5G Standalone Deployments
Publication Date: September 18, 2026
Author: TelcoSec Threat Research Team
Advisory ID: TS-ADV-2026-004
Impacted Protocols: 3GPP TS 29.510 / TS 33.501 (5G Service Based Architecture)
Executive Summary
Security researchers at the TelcoSec Research Group have identified a critical authorization bypass pattern affecting early Release 16/17 5G Standalone (SA) Core deployments. When Network Functions (NFs) register with the central Network Repository Function (NRF) via the nnrf-nfm service, improper validation of OAuth2 JSON Web Tokens (JWT) allows rogue network elements to advertise themselves as authoritative AMFs or SMFs.
Technical Analysis
Under 3GPP specification TS 33.501, every NF discovery request across the Service-Based Interface (SBI) must be authorized by an access token issued by the NRF containing audience claims (aud) specifying the target NF type and NF instance ID.
+----------------+ 1. Discovery Request (No Token) +----------------+
| Rogue 5G NF | -----------------------------------------> | 5G NRF Node |
| (TelcoChisel) | <----------------------------------------- | (SBI Gateway) |
| | 2. 200 OK with All Core Profiles | |
+----------------+ +----------------+
When an operator misconfigures the NRF service-authorization.strict-mode: false fallback flag, the NRF accepts unsigned discovery queries, disclosing the full internal IP topology and cryptographic certificates of all active UDM, AUSF, and UPF instances.
Mitigation & Remediation Guidelines
- Enforce Mutual TLS (mTLS): Mandate strict bidirectional X.509 certificate validation across all N32 and SBI interfaces.
- Strict Audience Checking: Validate
audandscopeclaims in every received JWT token at the target Service Producer. - Audit with TelcoChisel:
# Run automated SBA OAuth2 token validation audit telcochisel-5g-audit --nrf http://10.0.0.1:7777 --check-auth-bypass
Hands-on Simulation
Operators and penetration testers can simulate this attack and test mitigation patches in the TelcoSec Academy 5G SBA Red Team Lab.