CVE-2026-30078: Input Validation
OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message specification requires InitiatingMessage but sent with successfulOutcome.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30078?
CVE-2026-30078 is classified as a high severity vulnerability that can cause the OpenAirInterface V2.2.0 AMF to crash.
How do I fix CVE-2026-30078?
To fix CVE-2026-30078, it is recommended to upgrade to a newer version of the OpenAirInterface AMF that addresses this issue.
What types of messages cause CVE-2026-30078?
CVE-2026-30078 occurs when the OpenAirInterface AMF receives an NGAP message with an invalid procedure code or invalid PDU-type.
Which version of OpenAirInterface is affected by CVE-2026-30078?
CVE-2026-30078 specifically affects version 2.2.0 of the OpenAirInterface OAI-CN5G-AMF.
What are the consequences of CVE-2026-30078?
The consequence of CVE-2026-30078 is a crash of the AMF when it processes certain invalid NGAP messages.