CVE-2026-27643
Last modified
CVE-2026-27643 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, the NEF component reliably leaks internal parsing error details (e.g., invalid character 'n' after top-level value) to remote clients, which can aid attackers in service fingerprinting. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, the NEF component reliably leaks internal parsing error details (e.g., invalid character 'n' after top-level value) to remote clients, which can aid attackers in service fingerprinting. All deployments of free5GC using the Nnef_PfdManagement service may be affected. free5gc/udr pull request 56 contains a patch for the issue. There is no direct workaround at the application level. The recommendation is to apply the provided patch.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Free5gc | Udr | <= 1.4.1 |
References
- https://github.com/free5gc/free5gc/issues/753Exploit, Issue Tracking, Patch, Vendor Advisory
- https://github.com/free5gc/free5gc/security/advisories/GHSA-6468-f87j-6g82Patch, Vendor Advisory
- https://github.com/free5gc/udr/pull/56Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-27643?
How severe is CVE-2026-27643?
How do I fix CVE-2026-27643?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-27638Actual is a local-first personal finance tool. Prior to vers…7.1
- CVE-2026-27639Mercator is an open source web application designed to enabl…5.4
- CVE-2026-2764JIT miscompilation, use-after-free in the JavaScript Engine:…9.8
- CVE-2026-27640tfplan2md is software for converting Terraform plan JSON fil…7.5
- CVE-2026-27641Flask-Reuploaded provides file uploads for Flask. A critical…9.8
- CVE-2026-27642free5gc UDM provides Unified Data Management (UDM) for free5…7.5
- CVE-2026-27644Traccar is an open source GPS tracking system. In versions b…6.5
- CVE-2026-27645changedetection.io is a free open source web page change det…6.1
- CVE-2026-27646OpenClaw versions prior to 2026.3.7 contain a sandbox escape…6.1
- CVE-2026-27647The WebSocket backend uses charging station identifiers to u…9.8
- CVE-2026-27648in OpenHarmony v6.0 and prior versions allow a remote attack…8.8
- CVE-2026-27649The WebSocket backend uses charging station identifiers to u…6.5
Are you affected by CVE-2026-27643?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
