Information Disclosure Risk in Free5GC's UDR Service for 5G Mobile Networks
CVE-2026-40245

7.5HIGH

Key Information:

Vendor

Free5gc

Status
Vendor
CVE Published:
15 April 2026

What is CVE-2026-40245?

Free5GC, an open-source project for 5G core networks, is vulnerable to information disclosure stemming from its Unified Data Repository (UDR) service. In versions 4.2.1 and earlier, an unauthenticated attacker with network access can exploit this flaw through a parameterless HTTP GET request. The handler for a specific endpoint, when encountering missing query parameters, continues processing requests erroneously, leading to the leakage of sensitive subscriber identifiers such as the SUPI and IMSI values. This vulnerability significantly undermines subscriber privacy and violates 3GPP SUCI concealment principles, increasing the risk of unauthorized access to personal data.

Affected Version(s)

free5gc <= 1.4.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.