GHSA-wg4g-wm44-ch5jMedium
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
🔗 CVE IDs covered (1)
📋 Description
Impact
Remote denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message.
Patches
Upgrade to v3.1.4 or later. This version includes this patch https://github.com/pion/dtls/pull/839 which fixes the issue.
Workarounds
No work around; please upgrade to v3.1.4 or a newer version.
🎯 Affected products1
- go/github.com/pion/dtls/v3:<= 3.1.2
🔗 References (6)
- https://github.com/pion/dtls/security/advisories/GHSA-wg4g-wm44-ch5j
- https://nvd.nist.gov/vuln/detail/CVE-2026-54908
- https://github.com/pion/dtls/pull/839
- https://github.com/pion/dtls/commit/49458d604a4f3ebce1bf9587a0f3e5f3f6b4a55e
- https://github.com/pion/dtls/releases/tag/v3.1.3
- https://github.com/advisories/GHSA-wg4g-wm44-ch5j