<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T12:16:21.362108+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322485</id>
    <title>EUVD-2026-322485</title>
    <updated>2026-10-07T12:16:21.410310+00:00</updated>
    <content>EUVD-2026-322485</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44475</id>
    <title>fkie_cve-2026-44475</title>
    <updated>2026-10-07T12:16:21.410347+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values. A malicious gNB can overwrite Ella Core's stored UE security capabilities for any UE with arbitrary values by sending a single crafted PathSwitchRequest. This vulnerability is fixed in 1.10.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44475"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pwfh-mqp3-pqwj</id>
    <title>GHSA-pwfh-mqp3-pqwj — Ella Core has a UE Security Capability bypass on NGAP PathSwitchRequest</title>
    <updated>2026-10-07T12:16:21.410382+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/ellanetworks/core</p>
<p>## Summary</p>
<p>Ella Core does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values. A malicious gNB can overwrite Ella Core's stored UE security capabilities for any UE with arbitrary values by sending a single crafted PathSwitchRequest.</p>
<p>## Impact</p>
<p>A gNB can corrupt Ella Core's stored UE security capabilities for a target UE.</p>
<p>## Fix</p>
<p>The PathSwitchRequest handler now compares the received UE Security Capabilities against Ella Core's locally stored values, preserves the stored values on mismatch, returns them in the PathSwitchRequestAcknowledge, and logs the event.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pwfh-mqp3-pqwj"/>
  </entry>
</feed>
