CVE-2026-8779
4.3 MEDIUMA vulnerability was determined in omec-project amf up to 2.1.3-dev
Published: 2026-05-18 · Last updated: 2026-05-18
Severity and scoring
- CVSS
- 4.3 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- CWE
- CWE-119
Description
A vulnerability was determined in omec-project amf up to 2.1.3-dev. Impacted is the function NGSetupRequest of the file ngap/handler.go. Executing a manipulation of the argument InformationElement can lead to memory corruption. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.2.0 is recommended to address this issue. The affected component should be upgraded. The same pull request fixes multiple security issues.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-8779
- [Other]https://github.com/omec-project/amf/
- [Other]https://github.com/omec-project/amf/issues/671
- [Other]https://github.com/omec-project/amf/pull/666
- [Other]https://github.com/omec-project/amf/releases/tag/v2.2.0
- [Other]https://vuldb.com/submit/811616
- [Other]https://vuldb.com/vuln/364403
- [Other]https://vuldb.com/vuln/364403/cti
Related CVEs
Same CWE
- CVE-2026-12330 — Incorrect boundary conditions in the Internationalization component (5.4 MEDIUM)
- CVE-2026-12329 — Memory safety bug fixed in Thunderbird ESR 140.12 (5.3 MEDIUM)
- CVE-2026-12327 — Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151 (7.3 HIGH)
- CVE-2026-12326 — Memory safety bugs present in Firefox 151 and Thunderbird 151 (7.3 HIGH)
- CVE-2026-12318 — Incorrect boundary conditions in the Libraries component in NSS (7.3 HIGH)