LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-41136

CVE-2026-41136 - Vulnerability Analysis

MediumCVSS: 5.3

Last Updated: April 23, 2026

free5GC AMF - Insecure Deserialization

Published: April 22, 2026Updated: April 23, 2026PoC AvailableRemote Exploitable

Overview

free5GC AMF < 1.4.3 contains an insecure deserialization caused by missing default case in Content-Type switch in HTTPUEContextTransfer handler, letting attackers send unsupported Content-Type to bypass deserialization, exploit requires crafted request.

Severity & Score

Severity: Medium
CVSS Score: 5.3

Impact

Attackers can bypass deserialization checks, potentially causing logic errors or unexpected behavior in processing uninitialized data.

Mitigation

Update to version 1.4.3 or later.

Details

CVE ID
CVE-2026-41136
Severity
Medium
CVSS Score
5.3
Type
insecure_deserialization
Status
confirmed

CWE

  • CWE-440

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N