CVE-2026-9300: omec-project amf Vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer
(updated )
A vulnerability has been found in omec-project amf up to 2.1.1. This affects an unknown part of the component NGSetupRequest Handler. Such manipulation leads to memory corruption. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. It is best practice to apply a patch to resolve this issue.
References
- github.com/advisories/GHSA-6p7m-c3mw-4gmw
- github.com/omec-project/amf
- github.com/omec-project/amf/commit/34bc6724acc97dba1f8691e586da95b042cb612d
- github.com/omec-project/amf/issues/679
- github.com/omec-project/amf/pull/666
- nvd.nist.gov/vuln/detail/CVE-2026-9300
- vuldb.com/submit/811841
- vuldb.com/vuln/365247
- vuldb.com/vuln/365247/cti
Code Behaviors & Features
Detect and mitigate CVE-2026-9300 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →