<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 02:27:54 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292382</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292382</link>
      <description>EUVD-2026-292382</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292382</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41136</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41136</link>
      <description>&lt;p&gt;free5GC AMF provides Access &amp;amp; Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Prior to version 1.4.3, the `HTTPUEContextTransfer` handler in `internal/sbi/api_communication.go` does not include a `default` case in the `Content-Type` switch statement. When a request arrives with an unsupported `Content-Type`, the deserialization step is silently skipped, `err` remains `nil`, and the processor is invoked with a completely uninitialized `UeContextTransferRequest` object. Version 1.4.3 contains a fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;free5GC AMF provides Access &amp;amp; Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Prior to version 1.4.3, the `HTTPUEContextTransfer` handler in `internal/sbi/api_communication.go` does not include a `default` case in the `Content-Type` switch statement. When a request arrives with an unsupported `Content-Type`, the deserialization step is silently skipped, `err` remains `nil`, and the processor is invoked with a completely uninitialized `UeContextTransferRequest` object. Version 1.4.3 contains a fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41136</guid>
    </item>
    <item>
      <title>GHSA-r99v-75p9-xqm5 — free5GC AMF: Missing default case in Content-Type switch in HTTPUEContextTransfer</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r99v-75p9-xqm5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/free5gc/amf&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `HTTPUEContextTransfer` handler in `internal/sbi/api_communication.go` does not include a `default` case in the `Content-Type` switch statement. When a request arrives with an unsupported `Content-Type`, the deserialization step is silently skipped, `err` remains `nil`, and the processor is invoked with a completely uninitialized `UeContextTransferRequest` object.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;In `internal/sbi/api_communication.go`, the `HTTPUEContextTransfer` function handles the `Content-Type` header with a switch statement that only covers `application/json` and `multipart/related`:&lt;/p&gt;
&lt;p&gt;```go
switch str[0] {
case applicationjson:
    err = openapi.Deserialize(ueContextTransferRequest.JsonData, requestBody, contentType)
case multipartrelate:
    err = openapi.Deserialize(&amp;amp;ueContextTransferRequest, requestBody, contentType)
// no default case
}&lt;/p&gt;
&lt;p&gt;if err != nil {
    // skipped entirely when Content-Type is unsupported
    c.JSON(http.StatusBadRequest, rsp)
    return
}&lt;/p&gt;
&lt;p&gt;s.Processor().HandleUEContextTransferRequest(c, ueContextTransferRequest)
```&lt;/p&gt;
&lt;p&gt;This is inconsistent with the two analogous handlers in the same file, `HTTPCreateUEContext` and `HTTPN1N2MessageTransfer`, which both correctly include a `default` branch:&lt;/p&gt;
&lt;p&gt;```go
default:
    err = fmt.Errorf(&amp;#34;wrong content type&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;The fix is simply to add the same `default` case to `HTTPUEContextTransfer`.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;With a free5GC deployment running, send a POST request to the UE context transfer endpoint using any unsupported `Co…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/free5gc/amf&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `HTTPUEContextTransfer` handler in `internal/sbi/api_communication.go` does not include a `default` case in the `Content-Type` switch statement. When a request arrives with an unsupported `Content-Type`, the deserialization step is silently skipped, `err` remains `nil`, and the processor is invoked with a completely uninitialized `UeContextTransferRequest` object.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;In `internal/sbi/api_communication.go`, the `HTTPUEContextTransfer` function handles the `Content-Type` header with a switch statement that only covers `application/json` and `multipart/related`:&lt;/p&gt;
&lt;p&gt;```go
switch str[0] {
case applicationjson:
    err = openapi.Deserialize(ueContextTransferRequest.JsonData, requestBody, contentType)
case multipartrelate:
    err = openapi.Deserialize(&amp;amp;ueContextTransferRequest, requestBody, contentType)
// no default case
}&lt;/p&gt;
&lt;p&gt;if err != nil {
    // skipped entirely when Content-Type is unsupported
    c.JSON(http.StatusBadRequest, rsp)
    return
}&lt;/p&gt;
&lt;p&gt;s.Processor().HandleUEContextTransferRequest(c, ueContextTransferRequest)
```&lt;/p&gt;
&lt;p&gt;This is inconsistent with the two analogous handlers in the same file, `HTTPCreateUEContext` and `HTTPN1N2MessageTransfer`, which both correctly include a `default` branch:&lt;/p&gt;
&lt;p&gt;```go
default:
    err = fmt.Errorf(&amp;#34;wrong content type&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;The fix is simply to add the same `default` case to `HTTPUEContextTransfer`.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;With a free5GC deployment running, send a POST request to the UE context transfer endpoint using any unsupported `Co…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r99v-75p9-xqm5</guid>
    </item>
  </channel>
</rss>
