Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40343

27
FAUCET Score

OVERVIEW CVE-2026-40343 is a fail-open request handling vulnerability in free5GC UDR (User Data Repository) versions up to and including 1.4.2, an open-source 5G mobile core network component. The flaw exists in the policy-data subscription endpoint where the service continues processing requests despite errors during request body retrieval or deserialization, potentially creating invalid or partially processed Policy Data notification subscriptions. SEVERITY The vulnerability appears to have a low attack complexity with network accessibility, though formal CVSS metrics are not yet assigned. The flaw's impact depends on downstream processor behavior, potentially allowing attackers to create malformed subscriptions that could disrupt notification mechanisms or introduce unexpected system states. The FAUCET Risk Score of 46/100 indicates moderate concern, and the EPSS score of 0.00038 suggests relatively low widespread exploitation likelihood. EXPLOITATION STATUS There is no evidence of active exploitation, with the vulnerability absent from the CISA Known Exploited Vulnerabilities catalog. No public exploit code has been reported. Community attention appears minimal, though as of publication no patched version is available, which may limit visibility and adoption of fixes once released. Organizations running affected free5GC versions should monitor for patches and consider implementing request validation controls.

Impacted Technologies

VendorProductVersion(s)CPE
<= 4.2.1CPE matchmatch criteria
cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:*
<= 1.4.2CPE matchmatch criteria
cpe:2.3:a:free5gc:udr:*:*:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
9.96%
Probability of exploitation in next 30 days
EPSS Percentile
95.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0995 is in the 94th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

goGHSA-jwch-w7wh-gqjmmedium

free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation

Apr 21, 2026

References

github.com / free5gc/free5gc/security/advisories/GHSA-jwch-w7wh-gqjm
MitigationPatchVendor Advisory