---
id: CVE-2026-82550
title: A security flaw has been discovered in Linux Foundation Magma 1.9.0
summary: >-
  A security flaw has been discovered in Linux Foundation Magma 1.9.0. This
  impacts an unknown function of the component NGSetupRequest Handler.
  Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in
  improper input va…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-20
published: '2026-08-30'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82550'
references:
  - url: 'https://github.com/magma/magma/issues/16023'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-82550'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/891576'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/397066'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/397066/cti'
    label: cna@vuldb.com
  - url: 'https://www.linuxfoundation.org/'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-08-31T01:00:16.831Z'
epss: 0.00701
epssPercentile: 0.51202
---

## Overview

A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in improper input validation. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
