GHSA-wg4g-wm44-ch5jMedium

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

Published
July 31, 2026
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Remote denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message.

Patches

Upgrade to v3.1.4 or later. This version includes this patch https://github.com/pion/dtls/pull/839 which fixes the issue.

Workarounds

No work around; please upgrade to v3.1.4 or a newer version.

🎯 Affected products1

  • go/github.com/pion/dtls/v3:<= 3.1.2

🔗 References (6)