CVE-2026-33065
Last modified
CVE-2026-33065 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream 400 Bad Request (from UDR) into a 500 Internal Server Error when handling DELETE requests with an empty supi path parameter. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream 400 Bad Request (from UDR) into a 500 Internal Server Error when handling DELETE requests with an empty supi path parameter. This leaks internal error handling behavior and makes it difficult for clients to distinguish between client-side errors and server-side failures. When a client sends a DELETE request with an empty supi (e.g., double slashes // in URL path), the UDM forwards the malformed request to UDR, which correctly returns 400. However, UDM propagates this as 500 SYSTEM_FAILURE instead of returning the appropriate 400 error to the client. This violates REST API best practices for DELETE operations. The issue has been patched in version 1.4.2.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Free5gc | Udm | < 1.4.2 |
References
- https://github.com/free5gc/free5gc/issues/783Exploit, Issue Tracking, Patch, Vendor Advisory
- https://github.com/free5gc/free5gc/security/advisories/GHSA-958m-gxmc-mccmPatch, Vendor Advisory
- https://github.com/free5gc/udm/pull/79Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33065?
How severe is CVE-2026-33065?
How do I fix CVE-2026-33065?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-3306An improper authorization vulnerability was identified in Gi…4.3
- CVE-2026-33060CKAN MCP Server is a tool for querying CKAN open data portal…5.7
- CVE-2026-33061Jexactyl is a customisable game management panel and billing…5.4
- CVE-2026-33062free5GC is an open source 5G core network. free5GC NRF prior…7.5
- CVE-2026-33063free5GC is an open source 5G core network. free5GC AUSF prio…7.5
- CVE-2026-33064Free5GC is an open-source Linux Foundation project for 5th g…7.5
- CVE-2026-33066SiYuan is a personal knowledge management system. In version…9
- CVE-2026-33067SiYuan is a personal knowledge management system. Versions 3…9
- CVE-2026-33068Claude Code is an agentic coding tool. Versions prior to 2.1…8.8
- CVE-2026-33069PJSIP is a free and open source multimedia communication lib…7.5
- CVE-2026-3307An authorization bypass vulnerability was identified in GitH…2.7
- CVE-2026-33070FileRise is a self-hosted web file manager / WebDAV server. …4.8
Are you affected by CVE-2026-33065?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
