CVE-2026-40249

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT handler for updating Policy Data notification subscriptions at /nudr-dr/v2/policy-data/subs-to-notify/{subsId} does not return after request body retrieval or deserialization errors. Although HTTP 500 or 400 error responses are sent, execution continues and the processor is invoked with a potentially uninitialized or partially initialized PolicyDataSubscription object. This fail-open behavior may allow unintended modification of existing Policy Data notification subscriptions with invalid or empty input, depending on downstream processor and storage behavior. A patched version was not available at the time of publication.
References
Link Resource
https://github.com/free5gc/free5gc/security/advisories/GHSA-gx38-8h33-pmxr Exploit Third Party Advisory Mitigation
Configurations

Configuration 1 (hide)

cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:*

History

21 Apr 2026, 13:51

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References () https://github.com/free5gc/free5gc/security/advisories/GHSA-gx38-8h33-pmxr - () https://github.com/free5gc/free5gc/security/advisories/GHSA-gx38-8h33-pmxr - Exploit, Third Party Advisory, Mitigation
CPE cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:*
First Time Free5gc free5gc
Free5gc

16 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-16 22:16

Updated : 2026-04-21 13:51


NVD link : CVE-2026-40249

Mitre link : CVE-2026-40249

CVE.ORG link : CVE-2026-40249


JSON object : View

Products Affected

free5gc

  • free5gc
CWE
CWE-636

Not Failing Securely ('Failing Open')

CWE-754

Improper Check for Unusual or Exceptional Conditions