Denial of Service Risk in Ella Core 5G Network Product by Ella Networks
CVE-2026-32319

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
12 March 2026

What is CVE-2026-32319?

Ella Core, a 5G core network solution by Ella Networks, is susceptible to a denial of service vulnerability. Earlier versions than 1.5.1 of Ella Core can crash when processing malformed NGAP/NAS messages under 7 bytes in length. This flaw allows an attacker to exploit the system by sending crafted messages to the service, resulting in a service disruption for all connected users without requiring authentication. Users are highly encouraged to upgrade to version 1.5.1 or later to mitigate this risk.

Affected Version(s)

core < 1.5.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.