Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33191

27
FAUCET Score

CVE-2026-33191 is a null byte injection vulnerability affecting Free5GC versions prior to 1.4.2, specifically within the UDM's Nudm_SubscriberDataManagement API. A remote attacker can inject URL-encoded null bytes (%00) into the `supi` path parameter, causing Go's URL parser to fail and resulting in a 500 Internal Server Error. Rated 8.6 HIGH on the CVSS scale, this vulnerability has a network attack vector and low attack complexity, allowing unauthenticated remote attackers to trigger a denial of service (DoS) condition. The issue stems from improper input validation, leading to a server error instead of a bad request response. There is currently no public exploit code available, nor is it listed on the CISA KEV catalog or Hot List, with its EPSS score indicating a very low probability of active exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.4.2CPE matchmatch criteria
cpe:2.3:a:free5gc:udm:*:*:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.35%
Probability of exploitation in next 30 days
EPSS Percentile
27.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-23
Model: v2026.06.15
This CVE's current EPSS score of 0.0035 is in the 9th percentile among its peer group of 51,455 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / free5gc/free5gc/security/advisories/GHSA-p9hg-pq3q-v9gv
PatchVendor Advisory
github.com / free5gc/udm/commit/88de9fa74a1b3f3522e53b4cfa2d184712ffa4ee
Patch