CVE-2026-33282
Summary
Ella Core panics when processing a malformed NGAP LocationReport message with ue-presence-in-area-of-interest event type and omitting the optional UEPresenceInAreaOfInterestList IE.
Impact
An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required.
Fix
Added IE presence verification to NGAP message handling.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/ellanetworks/core/security/advisories/GHSA-826q-wrq4-p23x, https://nvd.nist.gov/vuln/detail/CVE-2026-33282, https://github.com/ellanetworks/core
