PT-2026-34224 · Unknown · Free5Gc Udr

CVE-2026-41135

·

Published

2026-04-21

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions free5GC UDR versions prior to 1.4.3
Description A memory leak in the Policy Control Function (PCF) allows an unauthenticated attacker with network access to the PCF SBI interface to cause uncontrolled memory growth. By sending repeated HTTP requests to the 'OAM' endpoint, the attacker triggers a router.Use() call inside an HTTP handler that registers a new CORS middleware for every request, permanently expanding the Gin router handler chain. This results in progressive memory exhaustion and a Denial of Service, which prevents User Equipments (UEs) from obtaining Access and Mobility (AM) and Session Management (SM) policies, thereby blocking 5G session establishment.
Recommendations Update to version 1.4.3.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41135
GHSA-98CP-84M9-Q3QP
GO-2026-5278
OPENSUSE-SU-2026:21483-1

Affected Products

Free5Gc Udr