Home

Description

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} handler panics with a nil-pointer dereference when the upstream UDR call fails AND the consumer wrapper returns err != nil together with a nil *ProblemDetails. The handler's errPfdData != nil branch builds its own problemDetailsErr correctly, but immediately after it reads problemDetails.Cause (the OTHER value, which is nil in this branch) and panics. Gin recovery converts the panic into HTTP 500, so a single PATCH against this endpoint returns 500 instead of the intended controlled error response whenever UDR access is failing. This vulnerability is fixed in 4.2.2.

PUBLISHED Reserved 2026-05-05 | Published 2026-05-27 | Updated 2026-05-28 | Assigner GitHub_M




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-476: NULL Pointer Dereference

CWE-754: Improper Check for Unusual or Exceptional Conditions

Product status

< 4.2.2
affected

References

github.com/...ree5gc/security/advisories/GHSA-j59f-x285-69jx exploit

github.com/...ree5gc/security/advisories/GHSA-j59f-x285-69jx

github.com/free5gc/free5gc/issues/925

github.com/free5gc/nef/pull/22

github.com/...ommit/72a47f3fab4dffbd227f8d92c5f69dca93b610cb

cve.org (CVE-2026-44322)

nvd.nist.gov (CVE-2026-44322)

Download JSON