PT-2026-32976 · Free5Gc · Free5Gc

Published

2026-04-14

·

Updated

2026-04-17

·

CVE-2026-40249

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions free5GC versions 4.2.1 and earlier
Description A fail-open request handling flaw exists in the UDR service. The PUT handler for the endpoint '/nudr-dr/v2/policy-data/subs-to-notify/{subsId}' does not terminate execution after request body retrieval or deserialization errors. Specifically, the function HandlePolicyDataSubsToNotifySubsIdPut() continues to invoke the processor with a potentially uninitialized or partially initialized PolicyDataSubscription object even after sending HTTP 500 or 400 error responses. This behavior may allow unintended modification of existing Policy Data notification subscriptions using invalid or empty input, depending on the downstream processor and storage behavior.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40249
GHSA-GX38-8H33-PMXR

Affected Products

Free5Gc