A malformed message can crash the free5gc/amf and free5gc/ngap decoders via an index-out-of-range panic in aper.GetBitString.
go package report
Is github.com/free5gc/aper safe?
1 known vulnerability.
// reach
0 direct dependencies
none carry a known advisory
0 packages depend on it
an advisory here reaches each of them
Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage
Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.
cvss
not scored
severity out of 10
epss
0.00%
medium
chance of exploitation in 30 days, 53rd percentile of all CVEs
xyz score
not scored
CyberXYZ composite out of 10
fig. 01 — GHSA-59hj-62f5-fgmc, the advisory selected below
// 1 advisories
Checked 2026-10-01 at 00:03 UTC. The most recent advisory here was published 2022-11-02. Updated continuously from NVD, GHSA, OSV and CNA feeds.