CVE-2026-41136

free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Prior to version 1.4.3, the `HTTPUEContextTransfer` handler in `internal/sbi/api_communication.go` does not include a `default` case in the `Content-Type` switch statement. When a request arrives with an unsupported `Content-Type`, the deserialization step is silently skipped, `err` remains `nil`, and the processor is invoked with a completely uninitialized `UeContextTransferRequest` object. Version 1.4.3 contains a fix.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:free5gc:amf:*:*:*:*:*:go:*:*
cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-22 00:16

Updated : 2026-06-17 10:46


NVD link : CVE-2026-41136

Mitre link : CVE-2026-41136

CVE.ORG link : CVE-2026-41136


JSON object : View

Products Affected

free5gc

  • amf
  • free5gc
CWE
CWE-440

Expected Behavior Violation