CVE-2026-40343 MEDIUM

CVE-2026-40343: free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation

Vendor Free5Gc
Product udr
Weakness CWE-754
Published April 21, 2026
Last update April 22, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

What the vulnerability does

01Description

free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.2, a fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify` POST handler to continue processing requests even after request body retrieval or deserialization errors. This may allow unintended creation of Policy Data notification subscriptions with invalid, empty, or partially processed input, depending on downstream processor behavior. As of time of publication, a patched version is not available.

Key dates

02Disclosure timeline

April 21, 2026 CVE published
April 22, 2026 Record updated