Vulnerability Description
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote Denial of Service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message. This issue has been fixed in version 3.1.4.
Related Weaknesses (CWE)
References
- https://github.com/pion/dtls/pull/839
- https://github.com/pion/dtls/security/advisories/GHSA-wg4g-wm44-ch5j
FAQ
What is CVE-2026-54908?
CVE-2026-54908 is a documented vulnerability. Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote Denial of Service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange ...
How severe is CVE-2026-54908?
CVSS scoring is not yet available for CVE-2026-54908. Check NVD for updates.
Is there a patch for CVE-2026-54908?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.