omec-project amf NGAP Message dispatcher.go memory corruption
Published May 18, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.53%
Description
A vulnerability was identified in omec-project amf up to 2.1.3-dev. The affected element is an unknown function of the file ngap/dispatcher.go of the component NGAP Message Handler. The manipulation leads to memory corruption. The attack may be initiated remotely. The exploit is publicly available and might be used. Upgrading to version 2.2.0 is sufficient to fix this issue. It is suggested to upgrade the affected component. The same pull request fixes multiple security issues.
Affected products
-
- Version 2.1.3-devStatusaffectedConstraints-
- Version 2.2.0StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Omec-Project | Amf | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
github.com/omec-project/amf
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/omec-project/amf | 0 | not fixed |
Remediation
No remediation recorded yet.
References (10)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30727 Advisory
- https://github.com/advisories/GHSA-3x4g-259h-5p7c Advisory
- https://github.com/omec-project/amf product
- https://github.com/omec-project/amf/issues/670 exploitissue-tracking
- https://github.com/omec-project/amf/pull/666 issue-trackingpatch
- https://github.com/omec-project/amf/releases/tag/v2.2.0 patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-8780
- https://vuldb.com/submit/811617 third-party-advisory
- https://vuldb.com/vuln/364404 vdb-entry
- https://vuldb.com/vuln/364404/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30727 | Advisory | |
| https://github.com/advisories/GHSA-3x4g-259h-5p7c | Advisory | |
| https://github.com/omec-project/amf | product | |
| https://github.com/omec-project/amf/issues/670 | exploitissue-tracking | |
| https://github.com/omec-project/amf/pull/666 | issue-trackingpatch | |
| https://github.com/omec-project/amf/releases/tag/v2.2.0 | patch | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-8780 | ||
| https://vuldb.com/submit/811617 | third-party-advisory | |
| https://vuldb.com/vuln/364404 | vdb-entry | |
| https://vuldb.com/vuln/364404/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.