CVE-2026-33065Disclosure(free5gc / udm)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream 400 Bad Request (from UDR) into a 500 Internal Server Error when handling DELETE requests with an empty supi path parameter. This leaks internal error handling behavior and makes it difficult for clients to distinguish between client-side errors and server-side failures. When a client sends a DELETE request with an empty supi (e.g., double slashes // in URL path), the UDM forwards the malformed request to UDR, which correctly returns 400. However, UDM propagates this as 500 SYSTEM_FAILURE instead of returning the appropriate 400 error to the client. This violates REST API best practices for DELETE operations. The issue has been patched in version 1.4.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-209

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • udm

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-20); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
udm

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-22: 1Technical Details · 2026-03-20: 103-2003-22
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-221
General1
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-33065 Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream… https://www.cve.org/CVERecord?id=CVE-2026-33065

    Post summary

    A brief mention of CVE-2026-33065 related to Free5GC without detailed vulnerability information or mitigation guidance.

    00000166
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33065 - free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request Intel Report: https://ift.tt/FtAub81

    Post summary

    The alert announces CVE-2026-33065: free5GC UDM returns a 500 error when a DELETE sdm-subscriptions request has an empty supi path parameter; no PoC, exploit, patch, or evidence of active exploitation is provided.

    0000029
    334 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcudm-go-

Explore more