Input Validation Flaw in free5GC UDM Component Exposes Internal Details
CVE-2026-42459
7.7HIGH
What is CVE-2026-42459?
The free5GC UDM component in versions prior to 4.2.2 contains an input validation error that can be exploited via six GET handlers of the nudm-sdm service. An attacker can submit a malformed SUPI parameter, leading to a 500 Internal Server Error. This error reveals sensitive internal details of the infrastructure, compromising the integrity of the system.
Affected Version(s)
free5gc < 4.2.2
