Reference page — cumulative record through Thursday, August 20, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-37226
n/a n/a — FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node.
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N N H 7.5 .0064 48.1 —
AFFECTED
Product Versions Fixed
n/a n/a – —
TIMELINE
Apr 6 Reserved by mitre
Jun 1 EXPLOIT PUBLISHED — CVE-2026-37226. Public exploit reference added.
Jun 1 Published (CNA: mitre)
Description
FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup function returns NULL, which is enforced by assert() in Debug builds (SIGABRT) and dereferenced in Release builds (SIGSEGV). A remote unauthenticated attacker can crash the iApp process (port 36422) by sending a subscription request with an arbitrary global_e2_node_id.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| April 6, 2026 | Reserved | Reserved by mitre |
| June 1, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-37226. Public exploit reference added. |
| June 1, 2026 | Published | Published (CNA: mitre) |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| n/a | n/a | — | n/a | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-37226 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, August 20, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.