Two high-severity vulnerabilities in Free5GC's Unified Data Management (UDM) component can be exploited remotely to disrupt 5G core subscriber data services in versions prior to 1.4.2. CVE-2026-33191 is a null byte injection issue in the supi path parameter of the Nudm_SubscriberDataManagement API. By sending URL-encoded null bytes such as %00, an attacker can trigger Go's net/url parser to fail with an invalid control character in URL error, causing the application to return a 500 Internal Server Error instead of safely rejecting the request.
A second flaw, CVE-2026-33064, allows a remote attacker to crash the UDM service through a crafted POST request to the /sdm-subscriptions endpoint containing path traversal sequences and a large JSON payload. The bug stems from a nil pointer dereference in the DataChangeNotificationProcedure function in notifier.go, which can trigger a runtime panic and leave UDM unavailable until restart. Both issues were fixed in Free5GC 1.4.2, and both carry high availability impact because they enable denial-of-service conditions against a core 5G network function.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
Public records described two high-severity Free5GC UDM vulnerabilities in versions prior to 1.4.2: one causing 500 Internal Server Error through URL-encoded null bytes in the supi path parameter, and another causing a runtime panic through a crafted POST request with path traversal sequences and a large JSON payload. The disclosures linked the issues to denial-of-service impact and referenced the related advisories and fixing commits.
Free5GC version 1.4.2 fixed two UDM vulnerabilities affecting earlier versions: a null byte injection in the Nudm_SubscriberDataManagement API (CVE-2026-33191) and a nil pointer dereference in the DataChangeNotificationProcedure via /sdm-subscriptions (CVE-2026-33064). Both issues could be triggered remotely to disrupt UDM availability and cause denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.