Affected by GO-2026-4691
and 13 other vulnerabilities
GO-2026-4691: Ella Core: AMF DoS via malformed PathSwitchRequest with empty NR security capability bitstrings in github.com/ellanetworks/core
GO-2026-4692: Ella Core vulnerable to Unauthenticated AMF DoS via malformed InitialUEMessage with undersized integrity-protected NAS payload in github.com/ellanetworks/core
GO-2026-4776: Ella Core panics on malformed ULNASTransport Message without a Request Type in github.com/ellanetworks/core
GO-2026-4780: Ella Core panics on malformed NGAP Location Report in github.com/ellanetworks/core
GO-2026-4783: Ella Core panics on invalid PDU Session IDs in NGAP messages in github.com/ellanetworks/core
GO-2026-4872: Ella Core Panics during NAS Authentication Response/Failure with missing IEs in github.com/ellanetworks/core
GO-2026-4873: Ella Core has Privilege Escalation via Database Restore by NetworkManager role in github.com/ellanetworks/core
GO-2026-4874: Ella Core has a Denial of Service via SCTP connection cleanup deadlock in github.com/ellanetworks/core
GO-2026-4875: Ella Core panics when processing a crafted NGAP LocationReport message in github.com/ellanetworks/core
GO-2026-5177: Ella Core Panics Upon NGAP handover failure in github.com/ellanetworks/core
GO-2026-5502: Ella Core has handover failures during concurrent Security Mode Command in github.com/ellanetworks/core
GO-2026-5554: Ella Core has a UE Security Capability bypass on NGAP PathSwitchRequest in github.com/ellanetworks/core
GO-2026-5581: Ella Core Vulnerable to UE Downlink Redirection via Forged PDUSessionResourceSetupResponse in github.com/ellanetworks/core
GO-2026-5770: Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriber in github.com/ellanetworks/core