CVE-2026-33064CWE-478

free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference

High · published March 20, 2026

CVSS v4.0
8.7
EPSS
0%
Percentile
40.1
In the wild
Unconfirmed
What it is

Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to procedure panic caused by Nil Pointer Dereference in the /sdm-subscriptions endpoint. A remote attacker can cause the UDM service to panic and crash by sending a crafted POST request to the /sdm-subscriptions endpoint with a malformed URL path containing path traversal sequences (../) and a large JSON payload. The DataChangeNotificationProcedure function in notifier.go attempts to access a nil pointer without proper validation, causing a complete service crash with "runtime error: invalid memory address or nil pointer dereference". Exploitation would result in UDM functionality disruption until recovery by restart. This issue has been fixed in version 1.4.2.

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.00486 · 40.1th percentile
Weakness
CWE-478 · Missing Default Case in Multiple Condition Expression
Published
2026-03-20T08:00Z
EPSS history
Timeline
  • 20 MAR 08:00Z
    free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference
    cvelistv5