{"id":"CVE-2026-33064","aliases":["GHSA-7g27-v5wj-jr75","GO-2026-4757"],"url":"https://o3.security/vulnerability/CVE-2026-33064","summary":"free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference","details":"**Impact**  \nThis is a NULL Pointer Dereference vulnerability leading to Denial of Service.  \n- **Security Impact**: A remote attacker can cause the UDM service to panic and crash by sending a crafted POST request to the `/sdm-subscriptions` endpoint with a malformed URL path containing path traversal sequences (`../`) and a large JSON payload. The `DataChangeNotificationProcedure` function in `notifier.go` attempts to access a nil pointer without proper validation, causing a complete service crash with \"runtime error: invalid memory address or nil pointer dereference\".  \n- **Functional Impact**: The service crashes completely, requiring manual restart. All UDM functionality is disrupted until recovery.  \n- **Affected Parties**: All deployments of free5GC v4.0.1 using the UDM HTTP callback functionality.\n\n**Patches**  \nYes, the issue has been patched.  \nThe fix is implemented in PR free5gc/udm#78.  \nUsers should upgrade to the next release of free5GC that includes this commit.\n\n**Workarounds**  \nThere is no direct workaround at the application level. The recommendation is to apply the provided patch or implement API gateway-level filtering to block requests containing path traversal sequences.","published":"2026-03-20T08:00:31.755Z","modified":"2026-08-12T03:51:43.311163923Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/free5gc/udm","fixedVersion":"1.4.2"}],"fix":{"url":"https://github.com/free5gc/udm/commit/65d7070f4bfd016864cbbaefbd506bbc85d2fa92","label":"free5gc/udm@65d7070"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33064.json"},{"type":"ADVISORY","url":"https://github.com/free5gc/free5gc/security/advisories/GHSA-7g27-v5wj-jr75"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33064"},{"type":"REPORT","url":"https://github.com/free5gc/free5gc/issues/781"},{"type":"FIX","url":"https://github.com/free5gc/udm/commit/65d7070f4bfd016864cbbaefbd506bbc85d2fa92"},{"type":"FIX","url":"https://github.com/free5gc/udm/pull/78"},{"type":"PACKAGE","url":"https://github.com/free5gc/udm"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.311163923Z"}}