CVE-2026-30056 is a NULL pointer dereference vulnerability found in the AMF NGAP Dispatcher component of free5gc version 4.0.1. Attackers can exploit this vulnerability by sending crafted NGAP messages during the initialization of a new RAN (Radio Access Network) connection. Successful exploitation results in a Denial of Service (DoS) condition, effectively crashing or disrupting the affected 5G core network component. The vulnerability is present in the open-source 5G core network implementation free5gc. This type of vulnerability is particularly significant given free5gc's use in research and production 5G network environments. The issue has been documented on the free5gc GitHub issue tracker.