CVE-2026-33064General(free5gc / udm)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to procedure panic caused by Nil Pointer Dereference in the /sdm-subscriptions endpoint. A remote attacker can cause the UDM service to panic and crash by sending a crafted POST request to the /sdm-subscriptions endpoint with a malformed URL path containing path traversal sequences (../) and a large JSON payload. The DataChangeNotificationProcedure function in notifier.go attempts to access a nil pointer without proper validation, causing a complete service crash with "runtime error: invalid memory address or nil pointer dereference". Exploitation would result in UDM functionality disruption until recovery by restart. This issue has been fixed in version 1.4.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-478CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • udm

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-20); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
udm

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-22: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 103-2003-22
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-201
General1
2026-03-221
Disclosure1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33064 Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to procedure panic caused by N… https://www.cve.org/CVERecord?id=CVE-2026-33064

    Post summary

    The CVE was disclosed as affecting Free5GC versions prior to 1.4.2, where a procedure panic could occur. No PoC, exploit, or patch reference is provided.

    00000170
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33064 - free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference Intel Report: https://ift.tt/PjV5E9e

    Post summary

    An alert announces CVE-2026-33064, a nil-pointer‑dereference panic in free5GC UDM’s DataChangeNotification procedure; only the vulnerability description is shared, with no exploit, patch, or active‑use details.

    0000031
    334 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcudm-go-

Explore more