PT-2026-26467 · Go · Github.Com/Ellanetworks/Core

Published

2026-03-19

·

Updated

2026-03-19

·

CVE-2026-33281

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Summary

Ella Core panics when processing NGAP messages with invalid PDU Session IDs outside of 1-15.

Impact

An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required.

Fix

Added PDU Session ID validations during NGAP message handling.

Fix

Improper Validation of Array Index

Weakness Enumeration

Related Identifiers

CVE-2026-33281
GHSA-Q669-4GMV-G8MF

Affected Products

Github.Com/Ellanetworks/Core