---
id: CVE-2026-14624
title: A vulnerability was identified in omec-project amf up to 2.0.2/2.1.1
summary: >-
  A vulnerability was identified in omec-project amf up to 2.0.2/2.1.1. Impacted
  is an unknown function of the file /go/src/amf/ngap/handler.go of the
  component NGSetupRequest Handler. The manipulation leads to denial of service.
  It is pos…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-404
published: '2026-07-04'
updated: '2026-07-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14624'
references:
  - url: 'https://github.com/omec-project/amf/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/omec-project/amf/commit/34bc6724acc97dba1f8691e586da95b042cb612d
    label: cna@vuldb.com
  - url: 'https://github.com/omec-project/amf/issues/677'
    label: cna@vuldb.com
  - url: 'https://github.com/omec-project/amf/pull/666'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-14624'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/845349'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/376140'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/376140/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-07-04T21:57:46.878Z'
epss: 0.00545
epssPercentile: 0.43262
---

## Overview

A vulnerability was identified in omec-project amf up to 2.0.2/2.1.1. Impacted is an unknown function of the file /go/src/amf/ngap/handler.go of the component NGSetupRequest Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The identifier of the patch is 34bc6724acc97dba1f8691e586da95b042cb612d. To fix this issue, it is recommended to deploy a patch.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
