High severityGHSA Advisory· Published May 11, 2026· Updated May 11, 2026
Ella Core Vulnerable to UE Downlink Redirection via Forged PDUSessionResourceSetupResponse
CVE-2026-44473
Description
Summary
A radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does not verify the message arrived on the SCTP association bound to that UE's logical NG-connection, then creates a GTP tunnel towards that radio.
Impact
Downlink user-plane traffic for the targeted UE is redirected to the attacker's radio.
Fix
UE context lookups are now scoped to the sending radio's SCTP association.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/ellanetworks/coreGo | < 1.10.0 | 1.10.0 |
Affected products
1- Range: < 1.10.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.