Panic in free5GC 5G Core Network Implementation Due to UDR Handler Issue
CVE-2026-44324
6.5MEDIUM
What is CVE-2026-44324?
A flaw in the UDR handler of free5GC, an open-source 5G core network implementation, allows for a panic to occur on unsuccessful user data requests. When an authenticated request is made and the specified ueId does not exist in the UESubsCollection, the system incorrectly attempts to process a nil interface. This results in a panic scenario that triggers an HTTP 500 response. The issue continues to be exploitable despite returning a USER_NOT_FOUND status. The vulnerability has been addressed in version 4.2.2.
Affected Version(s)
free5gc < 4.2.2
