OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message specification requires InitiatingMessage but sent with successfulOutcome.
References
| Link | Resource |
|---|---|
| https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/issues/74 | Exploit Issue Tracking |
| https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/merge_requests/414 | Issue Tracking |
Configurations
History
10 Apr 2026, 18:26
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Openairinterface oai-cn5g-amf
Openairinterface |
|
| CPE | cpe:2.3:a:openairinterface:oai-cn5g-amf:2.2.0:*:*:*:*:*:*:* | |
| References | () https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/issues/74 - Exploit, Issue Tracking | |
| References | () https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/merge_requests/414 - Issue Tracking |
06 Apr 2026, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CWE | CWE-20 |
06 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-06 14:16
Updated : 2026-04-10 18:26
NVD link : CVE-2026-30078
Mitre link : CVE-2026-30078
CVE.ORG link : CVE-2026-30078
JSON object : View
Products Affected
openairinterface
- oai-cn5g-amf
CWE
CWE-20
Improper Input Validation
