All 5 CVE vulnerabilities found in dtls, with AI-generated Chinese analysis, references, and POCs.
Vendor: pion
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-54908 | Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message CWE-125 | - | - | 2026-07-01 |
| CVE-2026-26014 | Pion DTLS uses random nonce generation with AES GCM ciphers risks leaking the authentication key CWE-200 | 5.9 | Medium | 2026-02-11 |
| CVE-2022-29222 | Improper Certificate Validation in Pion DTLS CWE-295 | 5.9 | Medium | 2022-05-21 |
| CVE-2022-29189 | Buffer for inbound DTLS fragments has no limit CWE-120 | 5.3 | Medium | 2022-05-20 |
| CVE-2022-29190 | Header reconstruction method can be thrown into an infinite loop in Pion DTLS CWE-835 | 7.5 | High | 2022-05-20 |
All 5 known CVE vulnerabilities affecting dtls with full Chinese analysis, references, and POCs where available.