Invalid Request Handling in Free5GC UDM Component by Linux Foundation
CVE-2026-33065
6.9MEDIUM
What is CVE-2026-33065?
The Free5GC's UDM component in versions prior to 1.4.2 mishandles DELETE requests with an empty 'supi' path parameter by incorrectly converting a 400 Bad Request from UDR into a 500 Internal Server Error. This misleading response obfuscates the distinction between client-side and server-side errors, violating REST API best practices. Clients may receive inaccurate status codes, complicating error diagnosis and response management, especially when malformed requests are sent. The issue has been resolved in version 1.4.2.
Affected Version(s)
free5gc < 1.4.2
