CVE-2026-33192 impacts the User Data Management (UDM) component of Free5GC, versions prior to 1.4.2, by mishandling PATCH requests with an empty 'supi' path parameter. This flaw causes the UDM to incorrectly convert downstream 400 Bad Request errors into 500 Internal Server Errors and translates the PATCH method to PUT when forwarding to the User Data Repository (UDR). Rated Medium severity (CVSS 5.3), it has a network attack vector with low complexity and requires no privileges, leading to information disclosure by leaking internal error handling details. There is no evidence of active exploitation, nor is public exploit code available on platforms like Metasploit or ExploitDB. Community discussion and media coverage are minimal, and it is not present on CISA's KEV catalog or Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.2CPE matchmatch criteria | cpe:2.3:a:free5gc:udm:*:*:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.