Null Pointer Dereference in OMEC Project AMF NGAP Message Handler
CVE-2026-8782
Key Information:
- Vendor
Omec-project
- Status
- Vendor
- CVE Published:
- 18 May 2026
Badges
What is CVE-2026-8782?
A vulnerability has been identified in the OMEC Project's AMF, specifically within the NGAP Message Handler component. This flaw allows for a null pointer dereference, which can lead to significant security risks, including potential remote exploitation. Attackers may utilize publicly available exploits to manipulate the affected function in the 'ngap/handler.go' file. To mitigate these risks, it is crucial for users to upgrade to version 2.2.0, which addresses this and other related security issues.
Affected Version(s)
amf 2.1.3-dev
amf 2.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
