CVE-2026-33907

Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Response and Authentication Failure NAS message missing IEs. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. Version 1.7.0 added IE presence verification to NAS message handling.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ellanetworks:ella_core:*:*:*:*:*:*:*:*

History

20 Apr 2026, 12:32

Type Values Removed Values Added
CPE cpe:2.3:a:ellanetworks:ella_core:*:*:*:*:*:*:*:*
First Time Ellanetworks
Ellanetworks ella Core
References () https://github.com/ellanetworks/core/commit/52962660e3bd3e23c7e96b0da270ac1e0e705273 - () https://github.com/ellanetworks/core/commit/52962660e3bd3e23c7e96b0da270ac1e0e705273 - Patch
References () https://github.com/ellanetworks/core/releases/tag/v1.7.0 - () https://github.com/ellanetworks/core/releases/tag/v1.7.0 - Release Notes
References () https://github.com/ellanetworks/core/security/advisories/GHSA-55q8-2gwx-29pc - () https://github.com/ellanetworks/core/security/advisories/GHSA-55q8-2gwx-29pc - Vendor Advisory

27 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-27 21:17

Updated : 2026-06-17 10:38


NVD link : CVE-2026-33907

Mitre link : CVE-2026-33907

CVE.ORG link : CVE-2026-33907


JSON object : View

Products Affected

ellanetworks

  • ella_core
CWE
CWE-476

NULL Pointer Dereference