VendorsPiondtlsany version
Vulnerabilities

Pion DTLS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2019-20786
handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows remote attackers to inject arbitrary unencrypted data after handshake completion.
Published 2020-04-19 · Modified
9.8EPSS 0.030
CVE-2022-29190
Header reconstruction method can be thrown into an infinite loop in Pion DTLS
Published 2022-05-20 · Modified
7.5EPSS 0.017
CVE-2022-29222
Improper Certificate Validation in Pion DTLS
Published 2022-05-21 · Modified
7.5EPSS 0.008
CVE-2026-26014
Pion DTLS uses random nonce generation with AES GCM ciphers risks leaking the authentication key
Published 2026-02-11 · Analyzed
5.9EPSS 0.007
CVE-2022-29189
Buffer for inbound DTLS fragments has no limit
Published 2022-05-20 · Modified
5.3EPSS 0.021