PT-2026-80406 · Go · Github.Com/Pion/Dtls/V3

Published

2026-08-18

·

Updated

2026-08-18

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In github.com/pion/dtls/v3 before 3.1.4, MessageServerKeyExchange.Unmarshal does not verify that data remains after parsing the PSK identity hint when handling ECDHE PSK key exchange messages. A remote peer sending a crafted ServerKeyExchange message where the PSK hint consumes all remaining data triggers an index out of range runtime panic, causing a denial of service.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GO-2026-6165

Affected Products

Github.Com/Pion/Dtls/V3