github.com/apernet/hysteria/core
Hysteria is powerful, lightning-fast, and censorship-resistant open-source proxy software
Activity
- Latest release
- 3y ago
- Total releases
- 5
- Cadence
- ~2 months
- Last 12 months
- 0
Reach
- Stars
- 22.4k
Details
- First release
- Nov 26, 2022
| Version | Released | |
|---|---|---|
v1.3.5
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v1.3.5
patch
Dependencies (8)
|
|
v1.3.4
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v1.3.4
patch
Dependencies (8)
|
|
v1.3.3
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v1.3.3
patch
Dependencies (8)
|
|
v1.3.2
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v1.3.2
patch
Dependencies (9)
+ 1 more |
|
v1.3.1
initial
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v1.3.1
initial
Dependencies (9)
+ 1 more |