-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 HPE Aruba Networking Product Security Advisory =============================== Advisory ID: HPESBNW05077 CVE: CVE-2026-40912, CVE-2026-39806, CVE-2026-39803 Publication Date: 2026-JUL-07 Status: FINAL Severity: HIGH Revision: 1 Title ===== Multiple Vulnerabilities in HPE Aruba Networking Private 5G Core Overview ======== HPE Aruba Networking has released a software update for the HPE Aruba Networking Private 5G Core platform to address multiple security vulnerabilities. Affected Products ================= These vulnerabilities affect the following HPE Aruba Networking Private 5G Core software version unless specifically noted otherwise in the details section: - HPE Aruba Networking Private 5G Core 1.26.1.0 and below. Unaffected Products =================== Any other HPE Aruba Networking products not specifically listed above are not affected by these vulnerabilities. Details ======= StripPrefixRegex auth bypass via Path/RawPath desync (CVE-2026-40912) --------------------------------------------------------------------- There is a high severity authentication bypass vulnerability in Traefik's StripPrefixRegex middleware when used in combination with ForwardAuth, BasicAuth, or DigestAuth. The middleware matches the regex against the decoded URL path but uses the resulting byte length to slice the percent-encoded raw path. When a dot (or multiple dots) appears in the prefix portion of the URL, the raw path after stripping becomes a dot-segment (e.g. /./admin/secret). ForwardAuth receives this dot-segment path in X-Forwarded-Uri, which does not match the protected path patterns and therefore allows the request through. The backend then normalizes the dot-segment to the real path per RFC 3986 and serves the protected content. An unauthenticated attacker can exploit this against any backend that performs dot-segment normalization. Internal Reference: VULN-390 Severity: High CVSSv3.1 Base Score: 8.2 CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Discovery: This vulnerability was discovered by gouldnicholas. Unauthenticated DoS via chunked request trailers in Bandit HTTP/1 decoder (CVE-2026-39806) --------------------------------------------------------------------- A worker-pinning denial of service in Bandit's HTTP/1 chunked transfer decoder. Any unauthenticated client that sends a Transfer-Encoding: chunked request whose body ends with a trailer field (RFC 9112 7.1.2 explicitly permits this) causes the connection's worker process to spin forever in an infinite recursion. A handful of concurrent connections are sufficient to exhaust the listener pool and render the server unresponsive to all further traffic. Internal Reference: VULN-392 Severity: High CVSSv3.1 Base Score: 7.5 CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Discovery: This vulnerability was discovered by PJUllrich. Unauthenticated one-shot DoS via `Transfer-Encoding: chunked` (CVE-2026-39803) --------------------------------------------------------------------- Bandit's HTTP/1 chunked-body reader silently drops the request size cap that the application configures (e.g. Plug.Parsers' default 8 MB length:) and buffers the entire body in memory before the application sees it. An unauthenticated attacker can crash any Bandit-fronted Phoenix/Plug app (BEAM OOM) with a single Transfer-Encoding: chunked request to any URL. Internal Reference: VULN-393 Severity: High CVSSv3.1 Base Score: 7.3 CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Discovery: This vulnerability was discovered by zzb1388. Resolution ========== To resolve the vulnerabilities described above, HPE Aruba Networking recommends upgrading the software to the following version: - HPE Aruba Networking Private 5G Core 1.26.1.1 and above HPE Aruba Networking does not evaluate or patch HPE Aruba Networking Private 5G Core Software versions that have reached their End of Support (EoS) milestone. For more information about HPE Aruba Networking Telco Product Lifecycle and versioning policy, please visit: https://www.hpe.com/psnow/doc/4aa5-5978enw?jumpid=in_pdfviewer-psnow Workaround ========== To minimize the likelihood of an attacker exploiting this vulnerability, HPE Aruba Networking recommends that management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage. You may contact HPE Services - HPE Aruba Networking for assistance if needed. For more information, please visit HPE Networking Support Portal at https://networkingsupport.hpe.com/home Exploitation and Public Discussion ================================== HPE Aruba Networking recognizes that these CVEs have been widely discussed publicly. At this time, the company is not aware of any publicly available exploitation tools or techniques that specifically target the HPE Aruba Networking Private 5G Core Platform. Revision History ================ Revision 1 / 2026-JUL-07 / Initial release HPE Aruba Networking SIRT Security Procedures ============================== Complete information on reporting security vulnerabilities in HPE Aruba Networking products and obtaining assistance with security incidents is available at: http://www.hpe.com/support/security-response-policy For reporting NEW HPE Aruba Networking security issues, email can be sent to aruba-sirt@hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at: https://www.hpe.com/info/psrt-pgp-key (c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date given at the top of the text, provided that the redistributed copies are complete and unmodified, including all data and version information. -----BEGIN PGP SIGNATURE----- iQHLBAEBCAA1FiEEQT1cq06WWXH+NEKru7x8adyj7A4FAmpNAA0XHHNlY3VyaXR5 LWFsZXJ0QGhwZS5jb20ACgkQu7x8adyj7A66YgwAwE5eRRffVjAenyfEs7H8LQUu MZjvvojmuHLIcsm5kaWMCfX2krW4QG1BGEnxPEtyBosP2tNGaZ2neQuZzb+c5lNH W1T+tzukHCDNtPjP86ynKYa7JdjdTylwxJJ53cvg7N5P5cx6eu7F+UDIWbRMjSf6 WKZxZbpqArcAX165A8cU2OOZdYj0Prkm82HllmK6Owq3Z2bfBIKSZU05e73OvaYt Y8LK7g3kj97iKUZNIp88/qs08iBAG1lMPbF5Qjj4Ha1z4nhl1JYq8XBjiB4WCqJb KYzd/rHNeP7eeKd9JSAOJe3r6XvjEXbkUV1OhTGxEZT6lHTa0YVd8i9WAKomblQI Dokemg9HsexxNQl0SXgJO6x16S1ZwJKN+oRFb4+0xsQ+bflgXMXAFcjf9ESYKOov +ShHWQZsqIR0GUoNNyLoS41I+JWGuhytkK3mZ7cIS79N245k/0ArcUv5GHKx1Ln8 HqmaoP0f8yukLNse23G/qlS8bLrHxXjGuXTX23UH =ngLb -----END PGP SIGNATURE-----