<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T20:44:55.058900+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292383</id>
    <title>EUVD-2026-292383</title>
    <updated>2026-10-05T20:44:55.107444+00:00</updated>
    <content>EUVD-2026-292383</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40343</id>
    <title>fkie_cve-2026-40343</title>
    <updated>2026-10-05T20:44:55.107486+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.2, a fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify` POST handler to continue processing requests even after request body retrieval or deserialization errors. This may allow unintended creation of Policy Data notification subscriptions with invalid, empty, or partially processed input, depending on downstream processor behavior. As of time of publication, a patched version is not available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40343"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jwch-w7wh-gqjm</id>
    <title>GHSA-jwch-w7wh-gqjm — free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation</title>
    <updated>2026-10-05T20:44:55.107523+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/free5gc/udr</p>
<p>### Summary
A fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify` POST handler to continue processing requests even after request body retrieval or deserialization errors.</p>
<p>This may allow unintended creation of Policy Data notification subscriptions with invalid, empty, or partially processed input, depending on downstream processor behavior.</p>
<p>### Details
The endpoint `POST /nudr-dr/v2/policy-data/subs-to-notify` is intended to create a Policy Data notification subscription only after the HTTP request body has been successfully read and parsed into a valid `PolicyDataSubscription` object. [file:93]</p>
<p>In the free5GC UDR implementation, the function `HandlePolicyDataSubsToNotifyPost` in `NFs/udr/internal/sbi/api_datarepository.go` does not terminate execution after input-processing failures. [file:93]</p>
<p>The request flow is:</p>
<p>1. The handler calls `c.GetRawData()` to read the HTTP request body. [file:93]
2. If `GetRawData()` fails, the handler sends an HTTP 500 error response, but **does not return**. [file:93]
3. The handler then calls `openapi.Deserialize(policyDataSubscription, reqBody, "application/json")`. [file:93]
4. If deserialization fails, the handler sends an HTTP 400 error response, but again **does not return**. [file:93]
5. Execution continues and the handler still invokes `s.Processor().PolicyDataSubsToNotifyPostProcedure(c,policyDataSubscription)`. [file:93]</p>
<p>As a result, the endpoint operates in a fail-open manner…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jwch-w7wh-gqjm"/>
  </entry>
</feed>
