CVE-2026-54908: Pion Dtls

Medium severity, CVSS 6.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote Denial of Service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message. This issue has been fixed in version 3.1.4.

Affected products

  • Pion Dtls: before 3.1.4 (fixed in 3.1.4)

Published 2026-07-01. Last modified 2026-07-02.