Denial of Service Risk in Ella Core 5G Network Product by Ella Networks
CVE-2026-32319
7.5HIGH
What is CVE-2026-32319?
Ella Core, a 5G core network solution by Ella Networks, is susceptible to a denial of service vulnerability. Earlier versions than 1.5.1 of Ella Core can crash when processing malformed NGAP/NAS messages under 7 bytes in length. This flaw allows an attacker to exploit the system by sending crafted messages to the service, resulting in a service disruption for all connected users without requiring authentication. Users are highly encouraged to upgrade to version 1.5.1 or later to mitigate this risk.
Affected Version(s)
core < 1.5.1
