OpenAirInterface is a narrowly scoped telecommunications software project centered on 5G network components, particularly its core network and radio access implementations, that despite limited product breadth occupies a specialist role in emerging cellular infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through weakness classes including improper input validation, authentication bypass mechanisms, and buffer-overflow conditions that reflect the protocol-handling and access-control demands of network infrastructure code. Defenders deploying or testing this vendor's 5G implementations should treat authentication and input-handling issues as high-priority; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openairinterface over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-37232HIGH An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric calculation. The functions fill_RRU_PrbTotDl() and fill_RRU | Jun 1, 2026 | 8.6 | 34 | NO | NO |
CVE-2026-30079CRITICAL In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed completely. I | Apr 7, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-30078HIGH OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message specification requires Initiating | Apr 6, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-30080HIGH OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported integrity NIA1 and NIA2. But if an UE sends initial registratio | Apr 8, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-30075HIGH OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentication Response containing a NAS PDU with oversize response ( | Apr 8, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-30077HIGH OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistent for particular inputs. An example in | Mar 30, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-66786HIGH OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote attackers can send malicious JSON data to AMF's SBI interface t | Jan 7, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-65805HIGH OpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote attackers can launch a denial-of-service attack and potentiall | Jan 7, 2026 | 7.5 | 22 | NO | NO |
CVE-2025-26265MEDIUM A segmentation fault in openairinterface5g v2.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted UE Context Modification response. | Mar 27, 2025 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openairinterface.
Media articles that mention a CVE ID that affects a product developed by Openairinterface — matched by CVE ID, not by vendor name.