CVE-2026-42459: FREE5GC
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to validate the supi path parameter in six GET handlers of the nudm-sdm (Subscriber Data Management) service. An unauthenticated attacker can inject control characters into the SUPI parameter, causing UDM to forward a malformed request to UDR and return a 500 Internal Server Error response that exposes internal infrastructure details. This vulnerability is fixed in 4.2.2.
Affected products
- FREE5GC FREE5GC: before 4.2.2 (fixed in 4.2.2)
Published 2026-05-27. Last modified 2026-06-17.