github.com/pion/dtls/v2
DTLS 1.2 / 1.3 implementation for Go
Activity
- Latest release
- 2y ago
- Total releases
- 43
- Cadence
- ~17 days
- Last 12 months
- 0
Reach
- Stars
- 698
Details
- First release
- Nov 23, 2019
| Version | Released | |
|---|---|---|
v2.2.12
patch
1 CVE
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev |
v2.2.12
patch
Dependencies (4)
|
|
v2.2.11
patch
1 CVE
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev |
v2.2.11
patch
Dependencies (4)
|
|
v2.2.10
patch
1 CVE
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev |
v2.2.10
patch
Dependencies (4)
|
|
v2.2.9
patch
1 CVE
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev |
v2.2.9
patch
Dependencies (4)
|
|
v2.2.8
patch
1 CVE
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev |
v2.2.8
patch
Dependencies (4)
|
|
v2.2.7
patch
1 CVE
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev |
v2.2.7
patch
Dependencies (4)
|
|
v2.2.6
patch
1 CVE
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev |
v2.2.6
patch
Dependencies (5)
|
|
v2.2.5
patch
1 CVE
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev |
v2.2.5
patch
Dependencies (5)
|
|
v2.2.4
patch
1 CVE
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev |
v2.2.4
patch
Dependencies (5)
|
|
v2.2.3
patch
3 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev |
v2.2.3
patch
Dependencies (5)
|
|
v2.2.2
patch
3 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev |
v2.2.2
patch
Dependencies (5)
|
|
v2.2.1
patch
3 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev |
v2.2.1
patch
Dependencies (5)
|
|
v2.2.0
minor
3 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev |
v2.2.0
minor
Dependencies (5)
|
|
v2.1.5
patch
3 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev |
v2.1.5
patch
Dependencies (5)
|
|
v2.1.4
patch
4 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.1.4
patch
Dependencies (5)
|
|
v2.1.3
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.1.3
patch
Dependencies (6)
|
|
v2.1.2
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.1.2
patch
Dependencies (6)
|
|
v2.1.1
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.1.1
patch
Dependencies (6)
|
|
v2.1.0
minor
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.1.0
minor
Dependencies (6)
|
|
v2.0.13
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.13
patch
Dependencies (6)
|
|
v2.0.12
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.12
patch
Dependencies (6)
|
|
v2.0.11
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.11
patch
Dependencies (6)
|
|
v2.0.10
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.10
patch
Dependencies (6)
|
|
v2.0.9
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.9
patch
Dependencies (6)
|
|
v2.0.8
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.8
patch
Dependencies (6)
|
|
v2.0.7
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.7
patch
Dependencies (6)
|
|
v2.0.6
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.6
patch
Dependencies (6)
|
|
v2.0.5
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.5
patch
Dependencies (6)
|
|
v2.0.4
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.4
patch
Dependencies (6)
|
|
v2.0.3
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.3
patch
Dependencies (6)
|
|
v2.0.2
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.2
patch
Dependencies (6)
|
|
v2.0.1
patch
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.1
patch
Dependencies (5)
|
|
v2.0.0
initial
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.0
initial
Dependencies (5)
|
|
v2.0.0-rc.10
pre
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.0-rc.10
pre
Dependencies (5)
|
|
v2.0.0-rc.9
pre
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.0-rc.9
pre
Dependencies (5)
|
|
v2.0.0-rc.8
pre
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.0-rc.8
pre
Dependencies (5)
|
|
v2.0.0-rc.7
pre
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.0-rc.7
pre
Dependencies (5)
|
|
v2.0.0-rc.6
pre
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.0-rc.6
pre
Dependencies (5)
|
|
v2.0.0-rc.5
pre
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.0-rc.5
pre
Dependencies (3)
|
|
v2.0.0-rc.4
pre
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.0-rc.4
pre
Dependencies (3)
|
|
v2.0.0-rc.3
pre
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.0-rc.3
pre
Dependencies (3)
|
|
v2.0.0-rc.2
pre
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.0-rc.2
pre
Dependencies (3)
|
|
v2.0.0-rc.1
pre
6 CVEs
CVE-2026-26014
GO-2026-4479
GHSA-9f3f-wv7r-qc8r
Feb 19, 2026
Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls References Updated Feb 20, 2026 · Source: OSV.dev
GO-2023-1535
GHSA-hxp2-xqf3-v83h
Feb 13, 2023
Panic during unmarshal of Server Hello in github.com/pion/dtls/v2 Unmarshalling a Server Hello can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
GO-2023-1534
GHSA-4xgv-j62q-h3rj
Feb 13, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2 Unmarshalling a Hello Verify request can panic, which could allow a denial of service. Fixed in
2.2.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29190
GO-2022-0460
GHSA-cm8f-h6j3-p25c
Jul 01, 2022
Infinite loop in github.com/pion/dtls/v2 An attacker can send packets that send the DTLS server or client into an infinite loop. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29189
GO-2022-0461
GHSA-cx94-mrg9-rq4j
Jul 01, 2022
Unbounded memory consumption in github.com/pion/dtls/v2 Attacker can cause unbounded memory consumption. The Pion DTLS client and server buffer handshake data with no upper limit, permitting an attacker to cause unbounded memory consumption by sending an unterminated handshake. Fixed in
2.1.4
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29222
GO-2022-0462
GHSA-w45j-f832-hxvh
Jul 01, 2022
Improper validation of client certificates in github.com/pion/dtls/v2 Client-provided certificates are not correctly validated, and must not be trusted. DTLS client certificates must be accompanied by proof that the client possesses the private key for the certificate. The Pion DTLS server accepted client certificates unaccompanied by this proof, permitting an attacker to present any certificate and have it accepted as valid. Fixed in
2.1.5
Updated May 20, 2024 · Source: OSV.dev |
v2.0.0-rc.1
pre
Dependencies (3)
|