Vulnerability Description
OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message specification requires InitiatingMessage but sent with successfulOutcome.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openairinterface | Oai-Cn5G-Amf | 2.2.0 |
Related Weaknesses (CWE)
References
- https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/issues/74ExploitIssue Tracking
- https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/merge_requests/414Issue Tracking
FAQ
What is CVE-2026-30078?
CVE-2026-30078 is a vulnerability with a CVSS score of 7.5 (HIGH). OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message specification requires InitiatingMessage but sent wit...
How severe is CVE-2026-30078?
CVE-2026-30078 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-30078?
Check the references section above for vendor advisories and patch information. Affected products include: Openairinterface Oai-Cn5G-Amf.