Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

amf — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in amf, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of Common Weakness Enumeration (CWE) vulnerabilities associated with the amf product, serving as a critical resource for security analysts, developers, and system administrators. The collection encompasses a wide spectrum of security flaws, ranging from injection attacks and improper access control to cryptographic failures and resource management issues, ensuring a holistic view of the product’s risk profile. All data points are curated to reflect reported incidents and advisory disclosures spanning from the product’s initial release through the most recent updates, offering both historical context and current threat intelligence. By utilizing this interface, users can efficiently track vendor advisories to stay informed about patch releases and mitigation strategies for specific threat vectors. Additionally, the page facilitates a deeper understanding of specific weakness classes by detailing how they manifest within the amf architecture, helping teams prioritize remediation efforts based on severity and exploitability. Users may also look up the product’s complete vulnerability history to identify patterns, recurring issues, or trends that might indicate systemic design flaws or legacy code debts. This structured approach allows for proactive security management, enabling organizations to assess their exposure accurately and implement targeted defenses. The information presented here is derived from verified public sources and vendor communications, ensuring reliability and accuracy for informed decision-making without the noise of unverified reports.

Vendor: free5gc

CVE ID Title CVSS Severity Published
CVE-2026-14624 omec-project amf NGSetupRequest handler.go denial of service CWE-404 4.3 Medium 2026-07-04
CVE-2026-14623 omec-project amf NGAP Message RRCInactiveTransitionReport denial of service CWE-404 4.3 Medium 2026-07-04
CVE-2026-9301 omec-project amf NGReset Message memory corruption CWE-119 6.3 Medium 2026-05-23
CVE-2026-9300 omec-project amf NGSetupRequest memory corruption CWE-119 6.3 Medium 2026-05-23
CVE-2026-9299 omec-project amf handler.go PDUSessionResourceModifyIndication memory corruption CWE-119 6.3 Medium 2026-05-23
CVE-2026-9298 omec-project amf PathSwitchRequest memory corruption CWE-119 6.3 Medium 2026-05-23
CVE-2026-8783 omec-project amf dispatcher.go UERadioCapabilityCheckResponse null pointer dereference CWE-476 4.3 Medium 2026-05-18
CVE-2026-8782 omec-project amf NGAP Message handler.go null pointer dereference CWE-476 4.3 Medium 2026-05-18
CVE-2026-8781 omec-project amf handler.go RANConfiguration null pointer dereference CWE-476 4.3 Medium 2026-05-18
CVE-2026-8780 omec-project amf NGAP Message dispatcher.go memory corruption CWE-119 4.3 Medium 2026-05-18
CVE-2026-8779 omec-project amf handler.go NGSetupRequest memory corruption CWE-119 4.3 Medium 2026-05-18
CVE-2026-8349 omec-project amf NGAP Message memory corruption CWE-119 4.3 Medium 2026-05-11
CVE-2026-41136 free5GC AMF missing default case in Content-Type switch in HTTPUEContextTransfer CWE-440 9.8AI Critical AI 2026-04-21
CVE-2025-69248 free5GC has Array Index Out of Bounds in AMF Leading to Denial of Service CWE-129 7.5AI High AI 2026-02-23

All 14 known CVE vulnerabilities affecting amf with full Chinese analysis, references, and POCs where available.