CVE-2026-27642General(free5gc / udm)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, remote attackers can inject control characters (e.g., %00) into the supi parameter, triggering internal URL parsing errors (net/url: invalid control character). This exposes system-level error details and can be used for service fingerprinting. All deployments of free5GC using the UDM Nudm_UEAU service may be affected. free5gc/udm pull request 75 contains a fix for the issue. No direct workaround is available at the application level. Applying the official patch is recommended.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • udm

Threat summary

  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-02-24); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
udm

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-02-24: 2Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-05-07: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-01: 1Technical Details · 2026-05-07: 102-2402-2702-2803-0105-07
Signal classification2 categories
General
466.7%
Disclosure
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure1General1
2026-02-271
General1
2026-02-281
General1
2026-03-011
General1
2026-05-071
Disclosure1
Full discourse6 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27642 URL Parsing Vulnerability in free5gc UDM Service Enabling Information Disclosure https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27642

    Post summary

    A URL parsing vulnerability in the free5gc UDM service that can lead to information disclosure has been disclosed as CVE-2026-27642.

    0001057
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 free5GC UDM, Input Validation Bypass, #CVE-2026-27642 (Medium) https://dailycve.com/free5gc-udm-input-validation-bypass-cve-2026-27642-medium/

    Post summary

    CVE-2026-27642 describes an input validation bypass in free5GC UDM. The post provides the vulnerability type and severity but does not mention exploits, patches, or active attacks.

    0000036
    196 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-27642 (CVSS:6.6, HIGH) is Analyzed. free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co..https://nvd.nist.gov/vuln/detail/CVE-2026-27642 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-27642 with its CVSS score and notes it has been analyzed, but provides no further technical or exploit details.

    0000024
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-27642 (CVSS:6.6, HIGH) is Analyzed. free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co..https://nvd.nist.gov/vuln/detail/CVE-2026-27642 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post merely references CVE-2026-27642 with its CVSS score and a link to the NVD, lacking any technical depth or exploitation evidence.

    0000028
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-27642 (CVSS:6.6, HIGH) is Analyzed. free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co..https://nvd.nist.gov/vuln/detail/CVE-2026-27642 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post notes CVE‑2026‑27642 and its CVSS score but offers no details on exploitation, mitigation, or PoC.

    0000031
    173 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27642 free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1… https://www.cve.org/CVERecord?id=CVE-2026-27642

    Post summary

    The text only references CVE-2026-27642 and the affected free5gc UDM component, without offering additional details or actionable information.

    00000162
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcudm-go-

Explore more