github.com/free5gc/udr
Activity
- Latest release
- 2mo ago
- Total releases
- 16
- Cadence
- ~3 months
- Last 12 months
- 4
Reach
- Stars
- —
Details
- First release
- Jan 18, 2021
| Version | Released | |
|---|---|---|
v1.4.4
patch
7 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev |
v1.4.4
patch
Dependencies (15)
+ 7 more |
|
v1.4.3
patch
7 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev |
v1.4.3
patch
Dependencies (15)
+ 7 more |
|
v1.4.2
patch
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.4.2
patch
Dependencies (15)
+ 7 more |
|
v1.4.1
patch
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (15)
+ 7 more |
|
v1.4.0
minor
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (15)
+ 7 more |
|
v1.3.2
patch
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.3.2
patch
Dependencies (14)
+ 6 more |
|
v1.3.1
patch
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.3.1
patch
Dependencies (14)
+ 6 more |
|
v1.2.4
patch
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.2.4
patch
Dependencies (14)
+ 6 more |
|
v1.2.3
patch
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.2.3
patch
Dependencies (14)
+ 6 more |
|
v1.2.2
patch
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.2.2
patch
Dependencies (13)
+ 5 more |
|
v1.2.1
minor
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.2.1
minor
Dependencies (13)
+ 5 more |
|
v1.1.1
minor
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.1
minor
Dependencies (12)
+ 4 more |
|
v1.0.2
patch
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.2
patch
Dependencies (17)
+ 9 more |
|
v1.0.1
patch
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.1
patch
Dependencies (17)
+ 9 more |
|
v1.0.0
initial
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.0
initial
Dependencies (17)
+ 9 more |
|
v1.3.0
minor
9 CVEs
CVE-2026-40245
GO-2026-5722
GHSA-wrwh-rpq4-87hf
Jun 25, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40247
GO-2026-5741
GHSA-x5r2-r74c-3w28
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40249
GO-2026-5407
GHSA-gx38-8h33-pmxr
Jun 25, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40248
GO-2026-5470
GHSA-jgq2-qv8v-5cmj
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44324
GO-2026-5478
GHSA-jqfc-gwj5-3w63
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40343
GO-2026-5482
GHSA-jwch-w7wh-gqjm
Jun 25, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40246
GO-2026-5396
GHSA-g9cw-qwhf-24jp
Jun 25, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions in github.com/free5gc/udr References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47780
GO-2026-5178
GHSA-6gxq-gpr8-xgjp
Jun 25, 2026
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence in github.com/free5gc/udr free5GC UDR has improper Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44323
GO-2026-5131
GHSA-4rqf-grm6-vf75
Jun 25, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) in github.com/free5gc/udr Fixed in
1.4.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.3.0
minor
Dependencies (17)
+ 9 more |