MEDIUM GitHub
CVE-2026-54908
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
### Impact
Remote denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message.
### Patches
Upgrade to v3.1.4 or later. This version includes this patch https://github.com/pion/dtls/pull/839 which fixes the issue.
### Workarounds
No work around; please upgrade to v3.1.4 or a newer version.
Affected Products
- go/github.com/pion/dtls/v3 <= 3.1.2
References
- https://github.com/advisories/GHSA-wg4g-wm44-ch5j
- https://github.com/pion/dtls/security/advisories/GHSA-wg4g-wm44-ch5j
- https://nvd.nist.gov/vuln/detail/CVE-2026-54908
- https://github.com/pion/dtls/pull/839
This medium severity vulnerability was published on 2026-07-31 via GitHub. Affected: go/github.com/pion/dtls/v3 <= 3.1.2.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.