free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, the service reliably leaks detailed internal error messages (e.g., strconv.ParseInt parsing errors) to remote clients when processing invalid pduSessionId inputs. This exposes implementation details and can be used for service fingerprinting. All deployments of free5GC using the UDM Nudm_UECM DELETE service may be vulnerable. free5gc/udm pull request 76 contains a fix for the issue. No direct workaround is available at the application level. Applying the official patch is recommended.
History

Tue, 24 Feb 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 24 Feb 2026 00:00:00 +0000

Type Values Removed Values Added
Description free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, the service reliably leaks detailed internal error messages (e.g., strconv.ParseInt parsing errors) to remote clients when processing invalid pduSessionId inputs. This exposes implementation details and can be used for service fingerprinting. All deployments of free5GC using the UDM Nudm_UECM DELETE service may be vulnerable. free5gc/udm pull request 76 contains a fix for the issue. No direct workaround is available at the application level. Applying the official patch is recommended.
Title free5GC has Improper Error Handling in UDM, Leading to Information Exposure
Weaknesses CWE-754
References
Metrics cvssV4_0

{'score': 6.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-23T23:51:24.107Z

Reserved: 2025-12-30T14:07:18.370Z

Link: CVE-2025-69250

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-24T00:16:18.330

Modified: 2026-02-24T00:16:18.330

Link: CVE-2025-69250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.