LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-33064

free5gc · udm

Published
CVSS7.5
Severityhigh
WeaknessCWE-478
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to procedure panic caused by Nil Pointer Dereference in the /sdm-subscriptions endpoint. A remote attacker can cause the UDM service to panic and crash by sending a crafted POST request to the /sdm-subscriptions endpoint with a malformed URL path containing path traversal sequences (../) and a large JSON payload. The DataChangeNotificationProcedure function in notifier.go attempts to access a nil pointer without proper validation, causing a complete service crash with "runtime error: invalid memory address or nil pointer dereference". Exploitation would resu

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33064

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33064.