free5GC UDR Policy Data Subscription Fail-Open Request Handling Vulnerability

Vulnerability

A fail-open request handling vulnerability has been identified in the free5GC User Data Repository (UDR) service, specifically in versions through 1.4.2. The issue arises in the POST handler for the '/nudr-dr/v2/policy-data/subs-to-notify' endpoint, where the service continues to process requests despite encountering errors in retrieving or deserializing the request body. This flaw may lead to the unintended creation of Policy Data notification subscriptions with invalid, empty, or partially processed input, depending on how downstream processors handle such data.

Impact

Exploitation of this vulnerability may result in the creation of invalid or unintended Policy Data notification subscriptions, leading to inconsistent request handling and potential disruptions in subscription management.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/nudr-dr/v2/policy-data/subs-to-notify' endpoint with a malformed or incomplete JSON body. The request will be processed despite the input errors, allowing for the creation of a subscription with invalid data.

Added: Apr 22, 2026, 12:39 AM
Updated: Apr 22, 2026, 12:39 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.6
remediation
0.0
relevance
6.5
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.