Information Disclosure Risk in Free5GC's UDR Service for 5G Mobile Networks
CVE-2026-40245
7.5HIGH
What is CVE-2026-40245?
Free5GC, an open-source project for 5G core networks, is vulnerable to information disclosure stemming from its Unified Data Repository (UDR) service. In versions 4.2.1 and earlier, an unauthenticated attacker with network access can exploit this flaw through a parameterless HTTP GET request. The handler for a specific endpoint, when encountering missing query parameters, continues processing requests erroneously, leading to the leakage of sensitive subscriber identifiers such as the SUPI and IMSI values. This vulnerability significantly undermines subscriber privacy and violates 3GPP SUCI concealment principles, increasing the risk of unauthorized access to personal data.
Affected Version(s)
free5gc <= 1.4.2
