VendorsFree5GCudmany version
Vulnerabilities

Free5GC udm 1.2.0 for Go any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2026-33064
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference
Published 2026-03-20 · Analyzed
8.7EPSS 0.008
CVE-2026-33191
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error
Published 2026-03-20 · Analyzed
8.7EPSS 0.006
CVE-2026-33192
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques
Published 2026-03-20 · Analyzed
8.7EPSS 0.004
CVE-2026-27642
free5GC has Improper Input Validation in UDM UEAU Service
Published 2026-02-24 · Analyzed
7.5EPSS 0.007
CVE-2025-69252
free5GC has Null Pointer Dereference in UDM, Leading to Service Panic
Published 2026-02-23 · Analyzed
7.5EPSS 0.005
CVE-2025-69250
free5GC has Improper Error Handling in UDM, Leading to Information Exposure
Published 2026-02-23 · Analyzed
7.5EPSS 0.004
CVE-2023-46324
pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key.
Published 2023-10-23 · Modified
7.5EPSS 0.004
CVE-2026-33065
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request
Published 2026-03-20 · Analyzed
6.9EPSS 0.004
CVE-2025-69251
free5GC has Improper Input Validation in UDM, Leading to Information Exposure
Published 2026-02-23 · Analyzed
6.6EPSS 0.005