github.com/apernet/hysteria/core/v2
Hysteria is a powerful, lightning fast and censorship resistant proxy.
Activity
- Latest release
- 1d ago
- Total releases
- 21
- Cadence
- ~29 days
- Last 12 months
- 14
Reach
- Stars
- 22.2k
Details
- First release
- May 30, 2024
| Version | Released | |
|---|---|---|
v2.11.0
minor
1 CVE
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.11.0
minor
Dependencies (5)
|
|
v2.10.0
minor
1 CVE
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.10.0
minor
Dependencies (5)
|
|
v2.9.3
patch
1 CVE
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.9.3
patch
Dependencies (5)
|
|
v2.9.2
patch
1 CVE
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.9.2
patch
Dependencies (5)
|
|
v2.9.1
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.9.1
patch
Dependencies (5)
|
|
v2.9.0
minor
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.9.0
minor
Dependencies (5)
|
|
v2.8.2
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.8.2
patch
Dependencies (5)
|
|
v2.8.1
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.8.1
patch
Dependencies (5)
|
|
v2.8.0
minor
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.8.0
minor
Dependencies (5)
|
|
v2.7.1
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.7.1
patch
Dependencies (5)
|
|
v2.7.0
minor
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.7.0
minor
Dependencies (5)
|
|
v2.6.5
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.6.5
patch
Dependencies (5)
|
|
v2.6.4
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.6.4
patch
Dependencies (5)
|
|
v2.6.3
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.6.3
patch
Dependencies (5)
|
|
v2.6.2
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.6.2
patch
Dependencies (5)
|
|
v2.6.1
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.6.1
patch
Dependencies (5)
|
|
v2.6.0
minor
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.6.0
minor
Dependencies (5)
|
|
v2.5.2
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.5.2
patch
Dependencies (5)
|
|
v2.5.1
patch
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.5.1
patch
Dependencies (5)
|
|
v2.5.0
minor
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.5.0
minor
Dependencies (5)
|
|
v2.4.5
initial
2 CVEs
GO-2026-5809
GHSA-vgrc-hq28-p3xp
Jul 07, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF in github.com/apernet/hysteria/core. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.9.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5288
GHSA-9fw6-xgg2-mq9q
Jun 25, 2026
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled in github.com/apernet/hysteria/core Updated Jun 25, 2026 · Source: OSV.dev |
v2.4.5
initial
Dependencies (5)
|