Description
free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go validate the ueId path value with a regular expression whose final .+ alternative accepts every non-empty string instead of restricting identifiers to supported SUPI and GPSI formats. An actor with network reachability to the UDR SBI can submit a non-3GPP identifier to /nudr-dr/v2/subscription-data/{ueId}/context-data/ee-subscriptions, causing the identifier to pass validation and enter the normal create or query flow. The advisory does not independently establish whether authentication is required. Invalid identifiers can be persisted and retrieved as subscription records, enabling unauthorized data creation, UDR namespace pollution, persistent subscriber-metadata corruption, and interference with downstream components that trust stored identifiers to use valid 3GPP formats. The exposure is most relevant in lab, test, or loosely segmented service-based-interface deployments where direct UDR access is possible.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized persistence of arbitrary identifiers leading to data corruption and namespace pollution
Action: Apply Mitigation
AI Analysis

Impact

An overly permissive regular expression in free5GC’s UDR subscription handlers validates the ueId path parameter with a final "+" branch that accepts every non‑empty string instead of limiting it to 3GPP‑approved SUPI or GPSI formats, allowing any string to be used as a UE identifier. free5GC is an open‑source 5G core network implementation, and the affected releases are 4.2.3 and earlier. An actor with network reachability to the UDR SBI can submit a non‑3GPP identifier to /nudr-dr/v2/subscription-data/{ueId}/context-data/ee-subscriptions. Because the advisory does not confirm whether authentication is required, the vulnerability may be exploitable without prior authentication. Persisting such invalid identifiers creates or retrieves subscription records that contain forbidden identifiers, leading to namespace pollution, subscriber‑metadata corruption, and interference with downstream components that rely on the assumption that stored identifiers are valid 3GPP values. The exposure is most relevant in lab, test, or loosely segmented service‑based‑interface deployments where direct UDR access is possible.

Affected Systems

The issue exists in free5GC releases 4.2.3 earlier, specifically within the HandleCreateEeSubscriptions and HandleQueryeesubscriptions functions located in internal/sbi/api_datarepository.go.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate to high impact, while the EPSS score of < 1% shows a low but present probability of exploitation. The flaw is not listed in the CISA KEV catalog. An attacker with network reachability to the UDR SBI endpoint can leverage the permissive validation; authentication requirements are not explicitly defined, raising the possibility of unauthenticated exploitation. Once exploited, attackers can persist arbitrary identifiers, leading to namespace pollution, persistent data corruption, and potential denial of service to legitimate subscribers.

Generated by OpenCVE AI on September 20, 2026 at 16:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade free5GC to a patched release that corrects the ueId validation logic, such as version 4.3 or later.
  • Enable strong authentication and restrict access to the UDR SBI endpoint to trusted networks or endpoints only.
  • Implement additional input validation or firewall rules to reject non‑3GPP identifiers before they reach the UDR service.

Generated by OpenCVE AI on September 20, 2026 at 16:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6gxq-gpr8-xgjp free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence
History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Free5gc
Free5gc free5gc
Vendors & Products Free5gc
Free5gc free5gc

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go validate the ueId path value with a regular expression whose final .+ alternative accepts every non-empty string instead of restricting identifiers to supported SUPI and GPSI formats. An actor with network reachability to the UDR SBI can submit a non-3GPP identifier to /nudr-dr/v2/subscription-data/{ueId}/context-data/ee-subscriptions, causing the identifier to pass validation and enter the normal create or query flow. The advisory does not independently establish whether authentication is required. Invalid identifiers can be persisted and retrieved as subscription records, enabling unauthorized data creation, UDR namespace pollution, persistent subscriber-metadata corruption, and interference with downstream components that trust stored identifiers to use valid 3GPP formats. The exposure is most relevant in lab, test, or loosely segmented service-based-interface deployments where direct UDR access is possible.
Title free5GC: UDR Improper ueId validation in free5GC EE subscription handlers allows arbitrary identifier persistence
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T15:25:25.704Z

Reserved: 2026-05-19T22:36:16.883Z

Link: CVE-2026-47780

cve-icon Vulnrichment

Updated: 2026-09-15T15:25:21.363Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:15.843

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-47780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation