CVE-2026-41136 affects free5GC's AMF (Access & Mobility Management Function) component in versions prior to 1.4.3. The vulnerability exists in the HTTPUEContextTransfer handler, which fails to include a default case in its Content-Type switch statement. When requests arrive with unsupported Content-Type headers, the deserialization step is silently skipped, causing the processor to receive an uninitialized UeContextTransferRequest object instead of properly rejecting the request. The vulnerability presents a moderate risk profile with a FAUCET Risk Score of 33.0/100. While specific CVSS metrics are unavailable, the defect allows an unauthenticated attacker to send malformed requests that bypass input validation and deserialization controls. The potential impact includes denial of service, unexpected behavior, or potential information disclosure through processing of uninitialized data structures, though the exact consequences depend on downstream processing of the malformed object. This vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and shows no signs of active exploitation. The EPSS score of 0.00039 indicates minimal real-world exploitation probability. The issue has received limited community attention, likely due to its specific nature within a niche 5G core network project. Users should apply the available patch in version 1.4.3 to remediate the defect.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.3CPE matchmatch criteria | cpe:2.3:a:free5gc:amf:*:*:*:*:*:go:*:* | ||
<= 4.2.1CPE matchmatch criteria | cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.