CVE-2026-93307 Details
Description
A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to uncontrolled memory allocation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a bug report but has not responded yet.
A vulnerability in O-RAN-SC SMO OAM VES Collector, dated 2025-06-10, allows for uncontrolled memory allocation. This issue arises from a manipulation of the 'additionalFields.padding' argument, leading to resource exhaustion. The vulnerability can be exploited remotely, causing a denial-of-service by flooding the application with oversized payloads. The problem has been publicly disclosed, and the project has not yet responded to reports about this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 17, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lf-o-ran-sc.atlassian.net/browse/SMO-201 | CISA-ADP | Issue TrackingPermission RequiredVendor |
| https://vuldb.com/submit/942297 | CISA-ADP | Issue TrackingPermission Required |
| https://vuldb.com/submit/942306 | CISA-ADP | Issue TrackingPermission Required |
| https://gist.github.com/fklement/1c1ff92588944a021ceb2b5e894973c5 | [email protected] | ExploitTechnical Description |
| https://lf-o-ran-sc.atlassian.net/browse/SMO-201 | [email protected] | Issue TrackingPermission RequiredVendor |
| https://vuldb.com/cve/CVE-2026-93307 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/942297 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/submit/942306 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/406593 | [email protected] | Content Wall |
| https://vuldb.com/vuln/406593/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-789 | Memory Allocation with Excessive Size Value | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| O-RAN-SC SMO | 2025-06-10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | CISA-ADP |
| Sep 17, 2026 | New CVE Received | [email protected] |
Volerion