PT-2026-34214 · Unknown · Free5Gc Udr

Published

2026-04-21

·

Updated

2026-04-28

·

CVE-2026-40343

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions free5GC UDR versions prior to 1.4.3
Description A fail-open request handling flaw exists in the UDR service. The POST handler for the endpoint '/nudr-dr/v2/policy-data/subs-to-notify' continues to process requests even after encountering errors during request body retrieval or deserialization. Specifically, the function HandlePolicyDataSubsToNotifyPost fails to terminate execution after sending error responses, allowing the process to invoke the PolicyDataSubsToNotifyPostProcedure() routine with uninitialized, empty, or partially processed input. This may lead to the unintended creation of Policy Data notification subscriptions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the '/nudr-dr/v2/policy-data/subs-to-notify' endpoint to minimize the risk of exploitation.

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40343
GHSA-JWCH-W7WH-GQJM

Affected Products

Free5Gc Udr