<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 21:37:48 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-291881</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291881</link>
      <description>EUVD-2026-291881</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291881</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40249</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40249</link>
      <description>&lt;p&gt;free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT handler for updating Policy Data notification subscriptions at /nudr-dr/v2/policy-data/subs-to-notify/{subsId} does not return after request body retrieval or deserialization errors. Although HTTP 500 or 400 error responses are sent, execution continues and the processor is invoked with a potentially uninitialized or partially initialized PolicyDataSubscription object. This fail-open behavior may allow unintended modification of existing Policy Data notification subscriptions with invalid or empty input, depending on downstream processor and storage behavior. A patched version was not available at the time of publication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT handler for updating Policy Data notification subscriptions at /nudr-dr/v2/policy-data/subs-to-notify/{subsId} does not return after request body retrieval or deserialization errors. Although HTTP 500 or 400 error responses are sent, execution continues and the processor is invoked with a potentially uninitialized or partially initialized PolicyDataSubscription object. This fail-open behavior may allow unintended modification of existing Policy Data notification subscriptions with invalid or empty input, depending on downstream processor and storage behavior. A patched version was not available at the time of publication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40249</guid>
    </item>
    <item>
      <title>GHSA-gx38-8h33-pmxr — free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates aft…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gx38-8h33-pmxr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/free5gc/udr&lt;/p&gt;
&lt;p&gt;### Summary
A fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify/{subsId}` PUT handler to continue processing requests even after request body retrieval or deserialization errors.&lt;/p&gt;
&lt;p&gt;This may allow unintended modification of existing Policy Data notification subscriptions with invalid, empty, or partially processed input, depending on downstream processor behavior.&lt;/p&gt;
&lt;p&gt;### Details
The endpoint `PUT /nudr-dr/v2/policy-data/subs-to-notify/{subsId}` is intended to update an existing Policy Data notification subscription only after the HTTP request body has been successfully read and parsed into a valid `PolicyDataSubscription` object. [file:93]&lt;/p&gt;
&lt;p&gt;In the free5GC UDR implementation, the function `HandlePolicyDataSubsToNotifySubsIdPut` in`NFs/udr/internal/sbi/api_datarepository.go` does not terminate execution after input-processing failures. [file:93]&lt;/p&gt;
&lt;p&gt;The request flow is:&lt;/p&gt;
&lt;p&gt;1. The handler calls `c.GetRawData()` to read the HTTP request body. [file:93]
2. If `GetRawData()` fails, the handler sends an HTTP 500 error response, but **does not return**. [file:93]
3. The handler then calls `openapi.Deserialize(policyDataSubscription, reqBody, &amp;#34;application/json&amp;#34;)`. [file:93]
4. If deserialization fails, the handler sends an HTTP 400 error response, but again **does not return**. [file:93]
5. Execution continues and the handler still invokes `s.Processor().PolicyDataSubsToNotifySubsIdPutProcedure(c, subsId, policyDataSubscription)`. [file:93]…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/free5gc/udr&lt;/p&gt;
&lt;p&gt;### Summary
A fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify/{subsId}` PUT handler to continue processing requests even after request body retrieval or deserialization errors.&lt;/p&gt;
&lt;p&gt;This may allow unintended modification of existing Policy Data notification subscriptions with invalid, empty, or partially processed input, depending on downstream processor behavior.&lt;/p&gt;
&lt;p&gt;### Details
The endpoint `PUT /nudr-dr/v2/policy-data/subs-to-notify/{subsId}` is intended to update an existing Policy Data notification subscription only after the HTTP request body has been successfully read and parsed into a valid `PolicyDataSubscription` object. [file:93]&lt;/p&gt;
&lt;p&gt;In the free5GC UDR implementation, the function `HandlePolicyDataSubsToNotifySubsIdPut` in`NFs/udr/internal/sbi/api_datarepository.go` does not terminate execution after input-processing failures. [file:93]&lt;/p&gt;
&lt;p&gt;The request flow is:&lt;/p&gt;
&lt;p&gt;1. The handler calls `c.GetRawData()` to read the HTTP request body. [file:93]
2. If `GetRawData()` fails, the handler sends an HTTP 500 error response, but **does not return**. [file:93]
3. The handler then calls `openapi.Deserialize(policyDataSubscription, reqBody, &amp;#34;application/json&amp;#34;)`. [file:93]
4. If deserialization fails, the handler sends an HTTP 400 error response, but again **does not return**. [file:93]
5. Execution continues and the handler still invokes `s.Processor().PolicyDataSubsToNotifySubsIdPutProcedure(c, subsId, policyDataSubscription)`. [file:93]…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gx38-8h33-pmxr</guid>
    </item>
  </channel>
</rss>
