github.com/ellanetworks/core
Go6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/ellanetworks/corepage 1 of 1
- CVE-2026-33903MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.7.02026-03-27
Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted NGAP LocationReport message. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing…
- CVE-2026-33904MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.7.02026-03-27
Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification handler causes the entire AMF control plane to hang until the process is restarted. An attacker with access to the N2 i…
- CVE-2026-33906HIGHCVSS 7.2EG 7.2✓ Fixed in 1.7.02026-03-27
Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup and restore permission. The restore endpoint accepted any valid SQLite file without verifying its contents. A NetworkM…
- CVE-2026-33907MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.7.02026-03-27
Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Response and Authentication Failure NAS message missing IEs. An attacker able to send crafted NAS messages to Ella Core can …
- CVE-2026-34761MEDIUMCVSS 5.8EG 5.8✓ Fixed in 1.8.02026-04-02
Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP handover failure message. An attacker able to cause a gNodeB to send NGAP handover failure messages to Ella Core can cras…
- CVE-2026-34762LOWCVSS 2.7EG 2.7✓ Fixed in 1.8.02026-04-02
Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API accepts an IMSI identifier from both the URL path and the JSON request body but never verifies they match. This allows an a…
Check whether github.com/ellanetworks/core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/ellanetworks/core CVEs against the assets you own.
Start Free Scan →