Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-958m-gxmc-mccm | free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 20 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Mar 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream 400 Bad Request (from UDR) into a 500 Internal Server Error when handling DELETE requests with an empty supi path parameter. This leaks internal error handling behavior and makes it difficult for clients to distinguish between client-side errors and server-side failures. When a client sends a DELETE request with an empty supi (e.g., double slashes // in URL path), the UDM forwards the malformed request to UDR, which correctly returns 400. However, UDM propagates this as 500 SYSTEM_FAILURE instead of returning the appropriate 400 error to the client. This violates REST API best practices for DELETE operations. The issue has been patched in version 1.4.2. | |
| Title | free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request | |
| Weaknesses | CWE-209 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-20T12:49:42.321Z
Reserved: 2026-03-17T19:27:06.343Z
Link: CVE-2026-33065
Updated: 2026-03-20T12:44:42.503Z
Status : Awaiting Analysis
Published: 2026-03-20T08:16:12.430
Modified: 2026-03-20T13:37:50.737
Link: CVE-2026-33065
No data.
OpenCVE Enrichment
Updated: 2026-03-20T10:36:48Z
Github GHSA