216.73.217.22

CVE-2026-33192

· Published 20/03/2026 09:16 · Modified 20/03/2026 13:37

Labels: CVE-2026-33192 2026-03-20CVE-2026-33192CWE-209[email protected]

Essential information

Published
20/03/2026 09:16
Modified
20/03/2026 13:37
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream 400 Bad Request (from UDR) into a 500 Internal Server Error when handling PATCH requests with an empty supi path parameter. Additionally, the UDM incorrectly translates the PATCH method to PUT when forwarding to UDR, indicating a deeper architectural issue. This leaks internal error handling behavior, making it difficult for clients to distinguish between client-side errors and server-side failures. The issue has been patched in version 1.4.2.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
linux foundation / free5gc cpe:2.3:a:linux_foundation:free5gc:<1.4.2:*:*:*:*:*:*:*

References