Vulnerability Details CVE-2026-30078
OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message specification requires InitiatingMessage but sent with successfulOutcome.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.6%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-30078
-
cpe:2.3:a:openairinterface:oai-cn5g-amf:2.2.0