LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-41135

CVE-2026-41135 - Vulnerability Analysis

HighCVSS: 7.5

Last Updated: April 23, 2026

free5GC UDR - Denial of Service

Published: April 22, 2026Updated: April 23, 2026PoC AvailableRemote Exploitable

Overview

free5GC UDR < 1.4.3 contains a memory leak caused by repeated registration of CORS middleware in the HTTP handler, letting unauthenticated attackers with network access cause denial of service by exhausting memory.

Severity & Score

Severity: High
CVSS Score: 7.5

Impact

Unauthenticated attackers can cause memory exhaustion leading to denial of service and blocking 5G session establishment.

Mitigation

Upgrade to version 1.4.3 or later.

Details

CVE ID
CVE-2026-41135
Severity
High
CVSS Score
7.5
Type
undefined
Status
confirmed

CWE

  • CWE-400

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H