Improper Check for Unusual or Exceptional Conditions Affecting github.com/free5gc/pcf/internal/sbi/processor package, versions <1.4.2


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.4% (33rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMFREE5GCPCFINTERNALSBIPROCESSOR-16624706
  • published10 May 2026
  • disclosed8 May 2026
  • creditLinZiyuu

Introduced: 8 May 2026

CVE-2026-44316  (opens in a new tab)
CWE-476  (opens in a new tab)
CWE-754  (opens in a new tab)

How to fix?

Upgrade github.com/free5gc/pcf/internal/sbi/processor to version 1.4.2 or higher.

Overview

Affected versions of this package are vulnerable to Improper Check for Unusual or Exceptional Conditions in the HandleCreateSmPolicyRequest process when a downstream OpenAPI consumer call returns a 404 error and the response struct is nil. An attacker can cause the application to panic and return an HTTP 500 error by sending a crafted POST request that triggers a failed downstream lookup, such as providing an unknown dnn value. This is only exploitable if the endpoint is accessible without authentication due to missing inbound auth middleware.

CVSS Base Scores

version 4.0
version 3.1