Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/omec-project/amf
  4. ›
  5. CVE-2026-9300

CVE-2026-9300: omec-project amf Vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer

May 26, 2026 (updated June 30, 2026)

A vulnerability has been found in omec-project amf up to 2.1.1. This affects an unknown part of the component NGSetupRequest Handler. Such manipulation leads to memory corruption. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. It is best practice to apply a patch to resolve this issue.

References

  • github.com/advisories/GHSA-6p7m-c3mw-4gmw
  • github.com/omec-project/amf
  • github.com/omec-project/amf/commit/34bc6724acc97dba1f8691e586da95b042cb612d
  • github.com/omec-project/amf/issues/679
  • github.com/omec-project/amf/pull/666
  • nvd.nist.gov/vuln/detail/CVE-2026-9300
  • vuldb.com/submit/811841
  • vuldb.com/vuln/365247
  • vuldb.com/vuln/365247/cti

Code Behaviors & Features

Detect and mitigate CVE-2026-9300 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.7.1-0.20260421213846-34bc6724acc9

Fixed versions

  • 1.7.1-0.20260421213846-34bc6724acc9

Solution

Upgrade to version 1.7.1-0.20260421213846-34bc6724acc9 or above.

Impact 6.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

Source file

go/github.com/omec-project/amf/CVE-2026-9300.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 11 Jul 2026 00:18:55 +0000.