Medium severity6.3NVD Advisory· Published May 23, 2026· Updated Jul 23, 2026
CVE-2026-9300
CVE-2026-9300
Description
A vulnerability has been found in omec-project amf up to 2.1.1. This affects an unknown part of the component NGSetupRequest Handler. Such manipulation leads to memory corruption. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. It is best practice to apply a patch to resolve this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/omec-project/amfGo | < 1.7.1-0.20260421213846-34bc6724acc9 | 1.7.1-0.20260421213846-34bc6724acc9 |
Affected products
3- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-6p7m-c3mw-4gmwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-9300ghsaADVISORY
- github.com/omec-project/amf/commit/34bc6724acc97dba1f8691e586da95b042cb612dghsaWEB
- github.com/omec-project/amf/issues/679nvdWEB
- github.com/omec-project/amf/pull/666nvdWEB
- vuldb.com/submit/811841nvdWEB
- vuldb.com/vuln/365247nvdWEB
- vuldb.com/vuln/365247/ctinvdWEB
News mentions
1- Free5GC AMF: Four Memory Corruption CVEs Disclosed in NGAP HandlersVypr Intelligence · May 23, 2026