{"id":"CVE-2019-20786","aliases":["GHSA-7gfg-6934-mqq2","GO-2020-0038"],"url":"https://o3.security/vulnerability/CVE-2019-20786","summary":"Improper Authenication in Pion DTLS","details":"handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows remote attackers to inject arbitrary unencrypted data after handshake completion.","published":"2020-04-19T20:15:11.587Z","modified":"2026-08-07T14:53:09.586577Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.03012,"percentile":0.86735,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Go","name":"github.com/pion/dtls","fixedVersion":"1.5.2"}],"fix":{"url":"https://github.com/pion/dtls/commit/fd73a5df2ff0e1fb6ae6a51e2777d7a16cc4f4e0","label":"pion/dtls@fd73a5d"},"references":[{"type":"ADVISORY","url":"https://www.usenix.org/conference/usenixsecurity20/presentation/fiterau-brostean"},{"type":"FIX","url":"https://github.com/pion/dtls/commit/fd73a5df2ff0e1fb6ae6a51e2777d7a16cc4f4e0"},{"type":"FIX","url":"https://github.com/pion/dtls/compare/v1.5.1...v1.5.2"},{"type":"EVIDENCE","url":"https://www.usenix.org/system/files/sec20fall_fiterau-brostean_prepub.pdf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:53:09.586577Z"}}