Access and Mobility Management Function Vulnerability in free5GC by free5GC
CVE-2026-41136
5.5MEDIUM
What is CVE-2026-41136?
The Access & Mobility Management Function (AMF) component of free5GC is affected by a vulnerability in the HTTPUEContextTransfer handler located in internal/sbi/api_communication.go. Prior to version 1.4.3, when a request with an unsupported Content-Type is received, the absence of a default case in the switch statement results in the deserialization process being mistakenly skipped. This oversight allows for the invocation of the processor with an uninitialized UeContextTransferRequest object, potentially compromising the integrity of operations within the 5G mobile core network.
Affected Version(s)
amf < 1.4.3
