Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 Go

Ella Core panics on invalid PDU Session IDs in NGAP messages

GHSA-q669-4gmv-g8mf · CVE-2026-33281 · GO-2026-4783

Published · Modified

Description

Summary

Ella Core panics when processing NGAP messages with invalid PDU Session IDs outside of 1-15.

Impact

An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required.

Fix

Added PDU Session ID validations during NGAP message handling.

Ready to move

Start Securing

Free, no credit card | First findings in minutes