Impact
An overly permissive regular expression in free5GC’s UDR subscription handlers validates the ueId path parameter with a final "+" branch that accepts every non‑empty string instead of limiting it to 3GPP‑approved SUPI or GPSI formats, allowing any string to be used as a UE identifier. free5GC is an open‑source 5G core network implementation, and the affected releases are 4.2.3 and earlier. An actor with network reachability to the UDR SBI can submit a non‑3GPP identifier to /nudr-dr/v2/subscription-data/{ueId}/context-data/ee-subscriptions. Because the advisory does not confirm whether authentication is required, the vulnerability may be exploitable without prior authentication. Persisting such invalid identifiers creates or retrieves subscription records that contain forbidden identifiers, leading to namespace pollution, subscriber‑metadata corruption, and interference with downstream components that rely on the assumption that stored identifiers are valid 3GPP values. The exposure is most relevant in lab, test, or loosely segmented service‑based‑interface deployments where direct UDR access is possible.
Affected Systems
The issue exists in free5GC releases 4.2.3 earlier, specifically within the HandleCreateEeSubscriptions and HandleQueryeesubscriptions functions located in internal/sbi/api_datarepository.go.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate to high impact, while the EPSS score of < 1% shows a low but present probability of exploitation. The flaw is not listed in the CISA KEV catalog. An attacker with network reachability to the UDR SBI endpoint can leverage the permissive validation; authentication requirements are not explicitly defined, raising the possibility of unauthenticated exploitation. Once exploited, attackers can persist arbitrary identifiers, leading to namespace pollution, persistent data corruption, and potential denial of service to legitimate subscribers.
OpenCVE Enrichment
Github GHSA