OVERVIEW CVE-2026-40343 is a fail-open request handling vulnerability in free5GC UDR (User Data Repository) versions up to and including 1.4.2, an open-source 5G mobile core network component. The flaw exists in the policy-data subscription endpoint where the service continues processing requests despite errors during request body retrieval or deserialization, potentially creating invalid or partially processed Policy Data notification subscriptions. SEVERITY The vulnerability appears to have a low attack complexity with network accessibility, though formal CVSS metrics are not yet assigned. The flaw's impact depends on downstream processor behavior, potentially allowing attackers to create malformed subscriptions that could disrupt notification mechanisms or introduce unexpected system states. The FAUCET Risk Score of 46/100 indicates moderate concern, and the EPSS score of 0.00038 suggests relatively low widespread exploitation likelihood. EXPLOITATION STATUS There is no evidence of active exploitation, with the vulnerability absent from the CISA Known Exploited Vulnerabilities catalog. No public exploit code has been reported. Community attention appears minimal, though as of publication no patched version is available, which may limit visibility and adoption of fixes once released. Organizations running affected free5GC versions should monitor for patches and consider implementing request validation controls.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2.1CPE matchmatch criteria | cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:* | ||
<= 1.4.2CPE matchmatch criteria | cpe:2.3:a:free5gc:udr:*:*:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.