A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGReset Message Handler. Performing a manipulation results in memory corruption. The attack is possible to be carried out remotely. The exploit has been made public and could be used. It is recommended to apply a patch to fix this issue.
Update github.com/omec-project/amf to 1.7.1-0.20260421213846-34bc6724acc9 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanomec-project amf Vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer affects github.com/omec-project/amf (go). Severity is low. A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGReset Message Handler. Performing a manipulation results in memory corruption. The attack is possible to be carried out remotely. The exploit has been made public and could be used. It is recommended to apply a patch to fix this issue.
AI coding agents often install or upgrade packages automatically in go. A low vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/omec-project/amfgo | <1.7.1-0.20260421213846-34bc6724acc9 |
A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGReset Message Handler. Performing a manipulation results in memory corruption. The attack is possible to be carried out remotely. The exploit has been made public and could be used. It is recommended to apply a patch to fix this issue.
Update github.com/omec-project/amf to 1.7.1-0.20260421213846-34bc6724acc9 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanomec-project amf Vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer affects github.com/omec-project/amf (go). Severity is low. A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGReset Message Handler. Performing a manipulation results in memory corruption. The attack is possible to be carried out remotely. The exploit has been made public and could be used. It is recommended to apply a patch to fix this issue.
AI coding agents often install or upgrade packages automatically in go. A low vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/omec-project/amfgo | <1.7.1-0.20260421213846-34bc6724acc9 |
| 1.7.1-0.20260421213846-34bc6724acc9 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 1.7.1-0.20260421213846-34bc6724acc9 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard