github.com/free5gc/udm
Activity
- Latest release
- 2mo ago
- Total releases
- 18
- Cadence
- ~3 months
- Last 12 months
- 5
Reach
- Stars
- —
Details
- First release
- Jan 18, 2021
| Version | Released | |
|---|---|---|
v1.4.5
patch
2 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.5
patch
Dependencies (13)
+ 5 more |
|
v1.4.4
patch
2 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.4
patch
Dependencies (13)
+ 5 more |
|
v1.4.3
patch
2 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.3
patch
Dependencies (13)
+ 5 more |
|
v1.4.2
patch
2 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.2
patch
Dependencies (13)
+ 5 more |
|
v1.4.1
patch
6 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (13)
+ 5 more |
|
v1.4.0
minor
6 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (13)
+ 5 more |
|
v1.3.2
patch
6 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.2
patch
Dependencies (12)
+ 4 more |
|
v1.3.1
patch
6 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.1
patch
Dependencies (13)
+ 5 more |
|
v1.2.5
patch
6 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.5
patch
Dependencies (14)
+ 6 more |
|
v1.2.4
patch
6 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.4
patch
Dependencies (14)
+ 6 more |
|
v1.2.3
patch
6 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.3
patch
Dependencies (14)
+ 6 more |
|
v1.2.2
patch
6 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.2
patch
Dependencies (13)
+ 5 more |
|
v1.2.1
minor
6 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.1
minor
Dependencies (11)
+ 3 more |
|
v1.1.1
minor
7 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46324
GHSA-cqvv-r3g3-26rf
Oct 23, 2023
free5GC udm vulnerable to Invalid Curve Attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key. Fixed in
1.2.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.1.1
minor
Dependencies (11)
+ 3 more |
|
v1.0.2
patch
7 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46324
GHSA-cqvv-r3g3-26rf
Oct 23, 2023
free5GC udm vulnerable to Invalid Curve Attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key. Fixed in
1.2.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.0.2
patch
Dependencies (18)
+ 10 more |
|
v1.0.1
patch
7 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46324
GHSA-cqvv-r3g3-26rf
Oct 23, 2023
free5GC udm vulnerable to Invalid Curve Attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key. Fixed in
1.2.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.0.1
patch
Dependencies (18)
+ 10 more |
|
v1.0.0
initial
7 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46324
GHSA-cqvv-r3g3-26rf
Oct 23, 2023
free5GC udm vulnerable to Invalid Curve Attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key. Fixed in
1.2.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.0.0
initial
Dependencies (18)
+ 10 more |
|
v1.3.0
minor
6 CVEs
CVE-2026-42459
GO-2026-5138
GHSA-585v-hcgf-jhfr
Jun 25, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information in github.com/free5gc/udm References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33065
GO-2026-4758
GHSA-958m-gxmc-mccm
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33192
GO-2026-4755
GHSA-5rvc-5cwx-g5x8
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33064
GO-2026-4757
GHSA-7g27-v5wj-jr75
Mar 23, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-33191
GO-2026-4763
GHSA-p9hg-pq3q-v9gv
Mar 23, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error in github.com/free5gc/udm Fixed in
1.4.2
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-60633
GO-2025-4162
GHSA-3j9f-7w24-pcqg
Dec 15, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API in github.com/free5gc/openapi References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.0
minor
Dependencies (18)
+ 10 more |