PT-2026-26209 · Free5Gc · Free5Gc
Zfei10990-Cmd
·
Published
2026-03-18
·
Updated
2026-03-27
·
CVE-2026-33192
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Free5GC versions prior to 1.4.2
Description
Free5GC’s UDM component exhibits improper error handling and HTTP method translation issues. Specifically, when handling PATCH requests to the
/sdm-subscriptions endpoint with an empty supi path parameter, the UDM incorrectly converts a 400 Bad Request (received from UDR) into a 500 Internal Server Error. Additionally, the UDM incorrectly translates the PATCH method to PUT when forwarding the request to UDR. This behavior leaks internal error handling details, making it difficult for clients to differentiate between client-side and server-side errors. The issue affects deployments using the UDM Nudm SDM service and impacts the handling of PATCH operations. The supi parameter in the API endpoint is vulnerable.Recommendations
Upgrade to Free5GC version 1.4.2 or later to address the issue. As a temporary workaround, implement API gateway-level validation to reject PATCH requests with empty path parameters before they reach the UDM.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Free5Gc