Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f2f3-9cx3-wcmf | Ella Core panics when processing a crafted NGAP LocationReport message |
Mon, 20 Apr 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks ella Core
|
|
| CPEs | cpe:2.3:a:ellanetworks:ella_core:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ellanetworks ella Core
|
Mon, 30 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks
Ellanetworks core |
|
| Vendors & Products |
Ellanetworks
Ellanetworks core |
Sat, 28 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted NGAP LocationReport message. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. Version 1.7.0 adds guards in NGAP Location Report handler. | |
| Title | Ella Core panics when processing a crafted NGAP LocationReport message | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-30T15:42:36.950Z
Reserved: 2026-03-24T15:41:47.491Z
Link: CVE-2026-33903
Updated: 2026-03-30T15:42:32.958Z
Status : Analyzed
Published: 2026-03-27T21:17:26.477
Modified: 2026-04-20T12:29:28.713
Link: CVE-2026-33903
No data.
OpenCVE Enrichment
Updated: 2026-03-30T07:00:15Z
Github GHSA