📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Artificial Intelligence and Technology HIGH 3h Global general Technology and Artificial Intelligence MEDIUM 6h Global general Technology and Artificial Intelligence HIGH 7h Global vulnerability Higher Education CRITICAL 16h Global data_breach Government HIGH 17h Global supply_chain Software Development and Open Source Communities CRITICAL 17h Global malware Software Development CRITICAL 17h Global phishing Multiple Sectors HIGH 18h Global vulnerability Web Applications CRITICAL 18h Global apt Critical Infrastructure CRITICAL 18h Global vulnerability Artificial Intelligence and Technology HIGH 3h Global general Technology and Artificial Intelligence MEDIUM 6h Global general Technology and Artificial Intelligence HIGH 7h Global vulnerability Higher Education CRITICAL 16h Global data_breach Government HIGH 17h Global supply_chain Software Development and Open Source Communities CRITICAL 17h Global malware Software Development CRITICAL 17h Global phishing Multiple Sectors HIGH 18h Global vulnerability Web Applications CRITICAL 18h Global apt Critical Infrastructure CRITICAL 18h Global vulnerability Artificial Intelligence and Technology HIGH 3h Global general Technology and Artificial Intelligence MEDIUM 6h Global general Technology and Artificial Intelligence HIGH 7h Global vulnerability Higher Education CRITICAL 16h Global data_breach Government HIGH 17h Global supply_chain Software Development and Open Source Communities CRITICAL 17h Global malware Software Development CRITICAL 17h Global phishing Multiple Sectors HIGH 18h Global vulnerability Web Applications CRITICAL 18h Global apt Critical Infrastructure CRITICAL 18h
Vulnerabilities

CVE-2026-40343

Medium
CWE-754 — Weakness Type
Published: Apr 22, 2026  ·  Modified: Apr 24, 2026  ·  Source: NVD
CVSS v3
5.8
🔗 NVD Official
📄 Description (English)

free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.2, a fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify` POST handler to continue processing requests even after request body retrieval or deserialization errors. This may allow unintended creation of Policy Data notification subscriptions with invalid, empty, or partially processed input, depending on downstream processor behavior. As of time of publication, a patched version is not available.

🤖 AI Executive Summary

free5GC UDR versions up to 1.4.2 contain a fail-open vulnerability in policy data notification subscription handling that allows invalid requests to be processed due to improper error handling. This could enable creation of malformed subscriptions that bypass intended validation, potentially disrupting 5G core network operations. While no public exploit exists, the vulnerability affects open-source 5G infrastructure commonly deployed in telecom environments.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 24, 2026 19:02
🇸🇦 Saudi Arabia Impact Assessment
Saudi telecom operators (STC, Mobily, Zain) deploying free5GC as part of 5G core network infrastructure are at direct risk. The vulnerability could compromise Policy Data notification subscriptions, affecting subscriber management and network service delivery. Government entities operating 5G networks and research institutions using free5GC for 5G development are also exposed. The fail-open behavior could lead to subscription database corruption, service disruptions, and potential unauthorized access to policy data flows.
🏢 Affected Saudi Sectors
Telecommunications 5G Infrastructure Operators Government (5G deployment) Research and Development Network Service Providers
⚖️ Saudi Risk Score (AI)
6.2
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Identify all free5GC UDR deployments in your 5G infrastructure and document versions
2. Implement network segmentation to restrict access to the `/nudr-dr/v2/policy-data/subs-to-notify` endpoint
3. Enable comprehensive logging and monitoring of UDR API requests and responses

Patching Guidance:
1. Upgrade free5GC to the latest patched version (verify patch availability from free5GC project)
2. Test patches in non-production environments before deployment
3. Coordinate upgrades with telecom operations to minimize service impact

Compensating Controls (if patch unavailable):
1. Implement API gateway validation to reject malformed requests before reaching UDR
2. Deploy Web Application Firewall (WAF) rules to validate request body structure and content
3. Implement strict input validation at the application layer
4. Use rate limiting on the affected endpoint to prevent abuse

Detection Rules:
1. Monitor for POST requests to `/nudr-dr/v2/policy-data/subs-to-notify` with empty or malformed JSON bodies
2. Alert on successful HTTP 200/201 responses following request body parsing errors
3. Track subscription creation events with null, empty, or incomplete policy data fields
4. Monitor UDR logs for deserialization errors followed by continued processing
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حدد جميع نشرات free5GC UDR في البنية التحتية 5G الخاصة بك وقم بتوثيق الإصدارات
2. طبق تقسيم الشبكة لتقييد الوصول إلى نقطة النهاية `/nudr-dr/v2/policy-data/subs-to-notify`
3. فعّل تسجيل المراقبة الشاملة لطلبات واستجابات API الخاصة بـ UDR

إرشادات التصحيح:
1. قم بترقية free5GC إلى أحدث إصدار مصحح (تحقق من توفر التصحيح من مشروع free5GC)
2. اختبر التصحيحات في بيئات غير الإنتاج قبل النشر
3. نسق الترقيات مع عمليات الاتصالات لتقليل تأثير الخدمة

الضوابط البديلة (إذا لم يكن التصحيح متاحاً):
1. طبق التحقق من بوابة API لرفض الطلبات المشوهة قبل وصولها إلى UDR
2. نشر قواعد جدار حماية تطبيقات الويب للتحقق من صحة هيكل ومحتوى نص الطلب
3. طبق التحقق الصارم من المدخلات على مستوى التطبيق
4. استخدم تحديد معدل على نقطة النهاية المتأثرة لمنع الإساءة

قواعد الكشف:
1. راقب طلبات POST إلى `/nudr-dr/v2/policy-data/subs-to-notify` مع أجسام JSON فارغة أو مشوهة
2. تنبيه على استجابات HTTP 200/201 الناجحة بعد أخطاء تحليل نص الطلب
3. تتبع أحداث إنشاء الاشتراك مع حقول بيانات السياسة الفارغة أو غير المكتملة أو الفارغة
4. راقب سجلات UDR لأخطاء إلغاء التسلسل متبوعة بمعالجة مستمرة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Network and Information Security Policies ECC 2024 A.5.2.1 - Access Control and Authentication ECC 2024 A.5.3.1 - Cryptography and Data Protection ECC 2024 A.5.4.1 - Logging and Monitoring
🔵 SAMA CSF
SAMA CSF ID.GV-1 - Organizational context and governance SAMA CSF PR.AC-1 - Access control policy and procedures SAMA CSF DE.CM-1 - Detection and monitoring systems SAMA CSF RS.CO-1 - Incident response coordination
🟡 ISO 27001:2022
ISO 27001:2022 A.5.15 - Access Control ISO 27001:2022 A.5.16 - Cryptography ISO 27001:2022 A.5.23 - Information Security for Supplier Relationships ISO 27001:2022 A.8.1 - User Endpoint Devices ISO 27001:2022 A.8.32 - Change Management
📦 Affected Products / CPE 2 entries
free5gc:free5gc
free5gc:udr
📊 CVSS Score
5.8
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeC — Changed
ConfidentialityN — None / Network
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score5.8
CWECWE-754
EPSS0.05%
Exploit No
Patch ✓ Yes
Published 2026-04-22
Source Feed nvd
Views 1
🇸🇦 Saudi Risk Score
6.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
patch-available CWE-754
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.