<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T01:00:44.662932+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-291881</id>
    <title>EUVD-2026-291881</title>
    <updated>2026-10-06T01:00:44.722068+00:00</updated>
    <content>EUVD-2026-291881</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-291881"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40249</id>
    <title>fkie_cve-2026-40249</title>
    <updated>2026-10-06T01:00:44.722111+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT handler for updating Policy Data notification subscriptions at /nudr-dr/v2/policy-data/subs-to-notify/{subsId} does not return after request body retrieval or deserialization errors. Although HTTP 500 or 400 error responses are sent, execution continues and the processor is invoked with a potentially uninitialized or partially initialized PolicyDataSubscription object. This fail-open behavior may allow unintended modification of existing Policy Data notification subscriptions with invalid or empty input, depending on downstream processor and storage behavior. A patched version was not available at the time of publication.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gx38-8h33-pmxr</id>
    <title>GHSA-gx38-8h33-pmxr — free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates aft…</title>
    <updated>2026-10-06T01:00:44.722149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/free5gc/udr</p>
<p>### Summary
A fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify/{subsId}` PUT handler to continue processing requests even after request body retrieval or deserialization errors.</p>
<p>This may allow unintended modification of existing Policy Data notification subscriptions with invalid, empty, or partially processed input, depending on downstream processor behavior.</p>
<p>### Details
The endpoint `PUT /nudr-dr/v2/policy-data/subs-to-notify/{subsId}` is intended to update an existing Policy Data notification subscription only after the HTTP request body has been successfully read and parsed into a valid `PolicyDataSubscription` object. [file:93]</p>
<p>In the free5GC UDR implementation, the function `HandlePolicyDataSubsToNotifySubsIdPut` in`NFs/udr/internal/sbi/api_datarepository.go` does not terminate execution after input-processing failures. [file:93]</p>
<p>The request flow is:</p>
<p>1. The handler calls `c.GetRawData()` to read the HTTP request body. [file:93]
2. If `GetRawData()` fails, the handler sends an HTTP 500 error response, but **does not return**. [file:93]
3. The handler then calls `openapi.Deserialize(policyDataSubscription, reqBody, "application/json")`. [file:93]
4. If deserialization fails, the handler sends an HTTP 400 error response, but again **does not return**. [file:93]
5. Execution continues and the handler still invokes `s.Processor().PolicyDataSubsToNotifySubsIdPutProcedure(c, subsId, policyDataSubscription)`. [file:93]…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gx38-8h33-pmxr"/>
  </entry>
</feed>
