OMEC Project AMF Memory Corruption Vulnerability in NGAP Message Handler

Vulnerability

A memory corruption vulnerability has been identified in the OMEC Project AMF component, specifically in versions up to 2.1.3-dev. The issue arises within an unknown function of the file 'ngap/dispatcher.go', related to the NGAP Message Handler. This vulnerability can be exploited remotely, and the exploit is publicly available.

Impact

Exploitation of this vulnerability leads to a crash of the AMF component, causing a denial of service.

Reproduction

The vulnerability can be reproduced by sending an NGAP packet that includes a non-printable string in the 'RANNodeName' information element of an 'NGSetupRequest'. This malformed input causes AMF to crash.

Remediation

Users are advised to upgrade to version 2.2.0 or later, where this vulnerability has been fixed.

Added: May 18, 2026, 2:20 AM
Updated: May 18, 2026, 2:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
8.7
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.