GHSA-6h8r-h22r-jj64

Suggest an improvement
Source
https://github.com/advisories/GHSA-6h8r-h22r-jj64
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-6h8r-h22r-jj64/GHSA-6h8r-h22r-jj64.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-6h8r-h22r-jj64
Aliases
Published
2026-05-18T03:31:49Z
Modified
2026-06-25T18:56:29Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
AMF Vulnerable to Improper Resource Shutdown or Release
Details

A weakness has been identified in omec-project amf up to 2.1.3-dev. This affects an unknown function of the file ngap/handler.go of the component NGAP Message Handler. This manipulation causes null pointer dereference. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.2.0 mitigates this issue. It is recommended to upgrade the affected component. The same pull request fixes multiple security issues.

Database specific
{
    "cwe_ids": [
        "CWE-404"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-28T22:43:02Z",
    "nvd_published_at": "2026-05-18T02:16:37Z",
    "severity": "LOW"
}
References

Affected packages

Go / github.com/omec-project/amf

Package

Name
github.com/omec-project/amf
View open source insights on deps.dev
Purl
pkg:golang/github.com/omec-project/amf

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-6h8r-h22r-jj64/GHSA-6h8r-h22r-jj64.json"