CVE-2026-33191 is a null byte injection vulnerability affecting Free5GC versions prior to 1.4.2, specifically within the UDM's Nudm_SubscriberDataManagement API. A remote attacker can inject URL-encoded null bytes (%00) into the `supi` path parameter, causing Go's URL parser to fail and resulting in a 500 Internal Server Error. Rated 8.6 HIGH on the CVSS scale, this vulnerability has a network attack vector and low attack complexity, allowing unauthenticated remote attackers to trigger a denial of service (DoS) condition. The issue stems from improper input validation, leading to a server error instead of a bad request response. There is currently no public exploit code available, nor is it listed on the CISA KEV catalog or Hot List, with its EPSS score indicating a very low probability of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.2CPE matchmatch criteria | cpe:2.3:a:free5gc:udm:*:*:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.