<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 04:10:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322209</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322209</link>
      <description>EUVD-2026-322209</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322209</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42083</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42083</link>
      <description>&lt;p&gt;free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI. In NewServer(), the smPolicyGroup route group is created and routes are applied without attaching the router authorization middleware. In contrast, other PCF service groups such as Npcf_PolicyAuthorization do attach RouterAuthorizationCheck before route registration. Because the middleware is missing, requests to the  /npcf-smpolicycontrol/v1/sm-policies, /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}, /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}/update, and /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}/delete endpoints can reach business logic even when no valid OAuth token is provided. This vulnerability is fixed in 4.2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI. In NewServer(), the smPolicyGroup route group is created and routes are applied without attaching the router authorization middleware. In contrast, other PCF service groups such as Npcf_PolicyAuthorization do attach RouterAuthorizationCheck before route registration. Because the middleware is missing, requests to the  /npcf-smpolicycontrol/v1/sm-policies, /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}, /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}/update, and /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}/delete endpoints can reach business logic even when no valid OAuth token is provided. This vulnerability is fixed in 4.2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42083</guid>
    </item>
    <item>
      <title>GHSA-6rgm-gr97-x3j5 — Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosu…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6rgm-gr97-x3j5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/free5gc/pcf&lt;/p&gt;
&lt;p&gt;### Summary
PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI
### Details
In `NewServer()`, the `smPolicyGroup` route group is created and routes are applied without attaching the router authorization middleware. In contrast, other PCF service groups such as `Npcf_PolicyAuthorization` do attach `RouterAuthorizationCheck` before route registration.&lt;/p&gt;
&lt;p&gt;Because the middleware is missing, requests to the following endpoints can reach business logic even when no valid OAuth token is provided:&lt;/p&gt;
&lt;p&gt;- `POST /npcf-smpolicycontrol/v1/sm-policies`
- `GET /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}`
- `POST /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}/update`
- `POST /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}/delete`&lt;/p&gt;
&lt;p&gt;This is visible at runtime because unauthenticated requests return business-level responses such as `400` or `404` instead of being rejected with `401` before handler execution. Under valid lab preconditions (existing UE/session context and related policy data), unauthenticated `POST /sm-policies` can succeed with `201`, and unauthenticated `GET /sm-policies/{id}` can succeed with `200` and return policy context containing subscriber identifiers including `supi`.&lt;/p&gt;
&lt;p&gt;The root cause is missing router auth enforcement for `Npcf_SMPolicyControl`. 
Upstream also fixed this by adding `RouterAuthorizationCheck` to `smPolicyGroup` (and `uePolicyGroup`) in free5gc/pcf PR #63.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/free5gc/pcf&lt;/p&gt;
&lt;p&gt;### Summary
PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI
### Details
In `NewServer()`, the `smPolicyGroup` route group is created and routes are applied without attaching the router authorization middleware. In contrast, other PCF service groups such as `Npcf_PolicyAuthorization` do attach `RouterAuthorizationCheck` before route registration.&lt;/p&gt;
&lt;p&gt;Because the middleware is missing, requests to the following endpoints can reach business logic even when no valid OAuth token is provided:&lt;/p&gt;
&lt;p&gt;- `POST /npcf-smpolicycontrol/v1/sm-policies`
- `GET /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}`
- `POST /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}/update`
- `POST /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}/delete`&lt;/p&gt;
&lt;p&gt;This is visible at runtime because unauthenticated requests return business-level responses such as `400` or `404` instead of being rejected with `401` before handler execution. Under valid lab preconditions (existing UE/session context and related policy data), unauthenticated `POST /sm-policies` can succeed with `201`, and unauthenticated `GET /sm-policies/{id}` can succeed with `200` and return policy context containing subscriber identifiers including `supi`.&lt;/p&gt;
&lt;p&gt;The root cause is missing router auth enforcement for `Npcf_SMPolicyControl`. 
Upstream also fixed this by adding `RouterAuthorizationCheck` to `smPolicyGroup` (and `uePolicyGroup`) in free5gc/pcf PR #63.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6rgm-gr97-x3j5</guid>
    </item>
  </channel>
</rss>
