{"id":"CVE-2026-42459","aliases":["GHSA-585v-hcgf-jhfr","GO-2026-5138"],"url":"https://o3.security/vulnerability/CVE-2026-42459","summary":"free5GC: Improper Input Validation and Generation of Error Message Containing Sensitive Information in github.com/free5gc/udm","details":"## Summary\n\nThe free5GC UDM component fails to validate the `supi` path parameter in six GET handlers of the `nudm-sdm` (Subscriber Data Management) service. An unauthenticated attacker can inject control characters into the SUPI parameter, causing UDM to forward a malformed request to UDR and return a `500 Internal Server Error` response that exposes internal infrastructure details.\n\n## Affected Package\n\n- **Ecosystem**: Go\n- **Package**: `github.com/free5gc/udm`\n- **Affected versions**: `<= v1.4.2`\n- **Patched versions**: none yet\n\n## Details\n\nThe following handlers in `internal/sbi/api_subscriberdatamanagement.go` do not call `validator.IsValidSupi()` before passing the `supi` parameter to the processor:\n\n- `HandleGetSmfSelectData` — `GET /:supi/smf-select-data`\n- `HandleGetSupi` — `GET /:supi`\n- `HandleGetTraceData` — `GET /:supi/trace-data`\n- `HandleGetUeContextInSmfData` — `GET /:supi/ue-context-in-smf-data`\n- `HandleGetNssai` — `GET /:supi/nssai`\n- `HandleGetSmData` — `GET /:supi/sm-data`\n\nBy contrast, `HandleGetAmData` in the same file correctly validates the `supi` parameter:\n\n```go\n// HandleGetAmData — correctly validates (not vulnerable)\nsupi := c.Params.ByName(\"supi\")\nif !validator.IsValidSupi(supi) {\n    c.JSON(http.StatusBadRequest, problemDetail)\n    return\n}\n\n// HandleGetSmfSelectData — missing validation (vulnerable)\nsupi := c.Params.ByName(\"supi\")\n// ← no validator.IsValidSupi(supi) call\ns.Processor().GetSmfSelectDataProcedure(c, supi, plmnID, supportedFeatures)\n```\n\nThe malformed `supi` is passed to the processor which constructs a URL to forward the request to UDR. Go's `net/url` parser rejects the URL containing control characters and returns an error. UDM catches this error and responds with a `500 SYSTEM_FAILURE` that includes the full internal UDR URL in the `detail` field.\n\n**This is a missed fix of CVE-2026-27642**, which applied the same `validator.IsValidSupi()` check only to `internal/sbi/api_ueauthentication.go` (`HandleConfirmAuth` and `HandleGenerateAuthData`), leaving the SDM service handlers unpatched.\n\n## Proof of Concept\n\n```bash\n# Vulnerable — returns 500 with internal UDR URL exposed\ncurl \"http://<UDM_HOST>/nudm-sdm/v2/imsi-22277%00INJECTED/smf-select-data\"\ncurl \"http://<UDM_HOST>/nudm-sdm/v2/imsi-22277%00INJECTED/nssai\"\ncurl \"http://<UDM_HOST>/nudm-sdm/v2/imsi-22277%00INJECTED/trace-data\"\ncurl \"http://<UDM_HOST>/nudm-sdm/v2/imsi-22277%00INJECTED/sm-data\"\n\n# Expected (vulnerable) response:\n# HTTP 500\n# {\n#   \"title\": \"System failure\",\n#   \"status\": 500,\n#   \"detail\": \"parse \\\"http://udr.internal:80/nudr-dr/v2/subscription-data/imsi-22277\\x00INJECTED//provisioned-data/smf-selection-subscription-data\\\": net/url: invalid control character in URL\",\n#   \"cause\": \"SYSTEM_FAILURE\"\n# }\n\n# Protected endpoint (for comparison) — returns 400\ncurl \"http://<UDM_HOST>/nudm-sdm/v2/imsi-22277%00INJECTED/am-data\"\n# HTTP 400\n# {\"title\":\"Malformed request syntax\",\"status\":400,\"detail\":\"Supi is invalid\",\"cause\":\"MANDATORY_IE_INCORRECT\"}\n```\n\n## Impact\n\nAn unauthenticated remote attacker can send a crafted GET request to any of the six affected endpoints to obtain:\n\n1. Internal UDR hostname and port\n2. Full internal API path structure (`/nudr-dr/v2/subscription-data/...`)\n3. UDR API version\n4. Internal service naming convention\n\nThis information can be used to facilitate further attacks against the UDR or other internal 5G core components.\n\n## Recommended Fix\n\nAdd `validator.IsValidSupi()` to all six affected handlers, following the pattern already used in `HandleGetAmData`:\n\n```go\nsupi := c.Params.ByName(\"supi\")\nif !validator.IsValidSupi(supi) {\n    problemDetail := models.ProblemDetails{\n        Title:  \"Malformed request syntax\",\n        Status: http.StatusBadRequest,\n        Detail: \"Supi is invalid\",\n        Cause:  \"MANDATORY_IE_INCORRECT\",\n    }\n    c.Set(sbi.IN_PB_DETAILS_CTX_STR, http.StatusText(int(problemDetail.Status)))\n    c.JSON(int(problemDetail.Status), problemDetail)\n    return\n}\n```","published":"2026-05-27T15:53:45.452Z","modified":"2026-09-04T03:46:46.802525215Z","cvss":null,"epss":{"score":0.00324,"percentile":0.25147,"asOf":"2026-08-14"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/free5gc/udm","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42459.json"},{"type":"ADVISORY","url":"https://github.com/free5gc/free5gc/security/advisories/GHSA-585v-hcgf-jhfr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42459"},{"type":"WEB","url":"https://github.com/free5gc/free5gc/security/advisories/GHSA-h4wg-rp7m-8xx4"},{"type":"PACKAGE","url":"https://github.com/free5gc/free5gc"},{"type":"WEB","url":"https://github.com/free5gc/udm/blob/v1.4.3/internal/sbi/api_subscriberdatamanagement.go"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-04T03:46:46.802525215Z"}}