Dtls
Pion · 6 CVEs
CVE-2026-54908
MEDIUM
Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Jul 1, 2026
CVE-2026-26014
MEDIUM
Pion DTLS uses random nonce generation with AES GCM ciphers risks leaking the authentication key
Feb 11, 2026
CVE-2022-29222
HIGH
Improper Certificate Validation in Pion DTLS
May 21, 2022
CVE-2022-29189
MEDIUM
Buffer for inbound DTLS fragments has no limit
May 20, 2022
CVE-2022-29190
HIGH
Header reconstruction method can be thrown into an infinite loop in Pion DTLS
May 20, 2022
CVE-2019-20786
CRITICAL
handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows…
Apr 19, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-54908 | Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message | MEDIUM | 0.54% | Jul 1, 2026 |
| CVE-2026-26014 | Pion DTLS uses random nonce generation with AES GCM ciphers risks leaking the authentication key | MEDIUM | 0.71% | Feb 11, 2026 |
| CVE-2022-29222 | Improper Certificate Validation in Pion DTLS | HIGH | 0.81% | May 21, 2022 |
| CVE-2022-29189 | Buffer for inbound DTLS fragments has no limit | MEDIUM | 2.12% | May 20, 2022 |
| CVE-2022-29190 | Header reconstruction method can be thrown into an infinite loop in Pion DTLS | HIGH | 1.72% | May 20, 2022 |
| CVE-2019-20786 | handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows remote attackers to inject arbitrary un… | CRITICAL | 3.01% | Apr 19, 2020 |
Showing 1 to 6 of 6 CVEs