Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.6

Free5GC UDM Crashes with Malicious Network Request

CVE-2025-69252
Summary

Free5GC's Unified Data Management (UDM) component may crash if a malicious network request is sent. This could cause disruptions to 5G mobile core network services. To prevent this, update the UDM component to a version newer than 1.4.1 or apply the patch found in pull request 76.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
free5gc udm <= 1.4.1 –
Original title
free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 have a NULL Pointer Dereferen...
Original description
free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 have a NULL Pointer Dereference vulnerability. Remote unauthenticated attackers can trigger a service panic (Denial of Service) by sending a crafted PUT request with an unexpected ueId, crashing the UDM service. All deployments of free5GC using the UDM component may be affected. free5gc/udm pull request 76 contains a fix for the issue. No direct workaround is available at the application level. Applying the official patch is recommended.
nvd CVSS3.1 7.5
nvd CVSS4.0 6.6
Vulnerability type
CWE-476 NULL Pointer Dereference
Published: 24 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026