PT-2026-32976 · Free5Gc · Free5Gc
Published
2026-04-14
·
Updated
2026-04-17
·
CVE-2026-40249
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
free5GC versions 4.2.1 and earlier
Description
A fail-open request handling flaw exists in the UDR service. The PUT handler for the endpoint '/nudr-dr/v2/policy-data/subs-to-notify/{subsId}' does not terminate execution after request body retrieval or deserialization errors. Specifically, the function
HandlePolicyDataSubsToNotifySubsIdPut() continues to invoke the processor with a potentially uninitialized or partially initialized PolicyDataSubscription object even after sending HTTP 500 or 400 error responses. This behavior may allow unintended modification of existing Policy Data notification subscriptions using invalid or empty input, depending on the downstream processor and storage behavior.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Free5Gc