PT-2026-54849 · Pion Dtls · Pion Dtls

·

CVE-2026-54908

·

Published

2026-07-01

·

Updated

2026-09-04

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Pion DTLS versions prior to 3.1.4
Description A remote denial of service occurs when the software parses a specially crafted ECDHE PSK ServerKeyExchange message, leading to a panic. A panic is a runtime error in Go that causes the program to crash.
Recommendations Update to version 3.1.4.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92112
CVE-2026-54908
GHSA-WG4G-WM44-CH5J
GO-2026-6165
OPENSUSE-SU-2026:21761-1

Affected Products

Pion Dtls