CVE-2026-40343Disclosure(free5gc / free5gc)

LOWCVSS 5.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.2, a fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify` POST handler to continue processing requests even after request body retrieval or deserialization errors. This may allow unintended creation of Policy Data notification subscriptions with invalid, empty, or partially processed input, depending on downstream processor behavior. As of time of publication, a patched version is not available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • free5gc
  • udr

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-21); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
free5gcudr

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Mentions · 2026-04-25: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-28: 104-2104-2204-2504-28
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Full discourse4 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-40343: CVE-2026-40343: Fail-Open Request Handling in free5GC UDR Policy Data Subscription A fail-open request handling vulnerability in the free5GC UDR service up to version 1.4.2 allows attackers to create invalid or unintended Policy Data n... https://cvereports.com/reports/CVE-2026-40343

    Post summary

    The text reports a fail‑open request handling vulnerability in free5GC UDR services up to v1.4.2, providing a brief technical description but no PoC, exploit, or mitigation details.

    0000022
    36 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40343 free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4… https://www.cve.org/CVERecord?id=CVE-2026-40343

    Post summary

    The post only links to the CVE record for free5GC UDR, providing no further information on the vulnerability itself, PoC, exploit, or mitigation.

    00000179
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40343 Fail-Open Request Handling Flaw in free5GC UDR Versions Up to 1.4.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40343 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    CVE-2026-40343 is a newly disclosed fail‑open request handling flaw affecting free5GC UDR up to version 1.4.2, with details posted on Vulmon but no PoC, exploit code, patch, or active exploitation information available.

    0000048
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 free5GC UDR, Fail-open request handling, #CVE-2026-40343 (Moderate) https://dailycve.com/free5gc-udr-fail-open-request-handling-cve-2026-40343-moderate/

    Post summary

    An informational disclosure of CVE‑2026‑40343, a fail‑open request handling vulnerability in the free5GC UDR component, rated moderate severity.

    0000040
    183 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcfree5gc---
Appfree5gcudr-go-

Explore more