CVE-2026-33192Disclosure(free5gc / udm)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch free5gc udm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream 400 Bad Request (from UDR) into a 500 Internal Server Error when handling PATCH requests with an empty supi path parameter. Additionally, the UDM incorrectly translates the PATCH method to PUT when forwarding to UDR, indicating a deeper architectural issue. This leaks internal error handling behavior, making it difficult for clients to distinguish between client-side errors and server-side failures. The issue has been patched in version 1.4.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-209

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • udm

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-20); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
udm

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-22: 1Mentions · 2026-03-25: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-22: 1Technical Details · 2026-03-25: 103-2003-2203-25
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure1Patch1
2026-03-221
Disclosure1
2026-03-251
Disclosure1
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    CVE-2026-33192 in `free5GC UDM` causes HTTP 500 errors for empty `supi` parameters in `PATCH` requests, potentially leading to service instability. Monitor for official patches. #5Gsecurity #APIsecurity https://www.pulsepatch.io/posts/cve-2026-33192-free5gc-udm-http-500-error

    Post summary

    The message announces CVE-2026-33192 in free5GC UDM, describing the error behavior and encouraging monitoring for vendor patches.

    0000052
    2 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33192 Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream… https://www.cve.org/CVERecord?id=CVE-2026-33192

    Post summary

    The text announces CVE-2026‑33192 affecting Free5GC UDM before version 1.4.2, notes a conversion error, but provides no PoC, exploit, or patch details.

    00000150
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33192 Free5GC UDM Improper Error Handling and Method Translation Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33192

    Post summary

    A newly disclosed vulnerability, CVE‑2026‑33192, affects Free5GC UDM via improper error handling and method translation; no exploit, patch, or active exploitation details are provided.

    0000038
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33192: HIGH] Free5GC project addresses critical UDM software vulnerabilities in 5G networks. Update to version 1.4.2 to patch issues translating HTTP responses and prevent error leakages.#cve,CVE-2026-33192,#cybersecurity https://cvefind.com/CVE-2026-33192

    Post summary

    Free5GC released version 1.4.2 to patch critical UDM software vulnerabilities affecting HTTP response translation and error leakages.

    0000044
    604 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcudm-go-

Explore more