{"id":"CVE-2026-54908","aliases":["GHSA-wg4g-wm44-ch5j","GO-2026-6165"],"url":"https://o3.security/vulnerability/CVE-2026-54908","summary":"Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message","details":"Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote Denial of Service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message. This issue has been fixed in version 3.1.4.","published":"2026-07-01T19:34:24.014Z","modified":"2026-09-09T18:26:45.394499423Z","cvss":null,"epss":{"score":0.00542,"percentile":0.43995,"asOf":"2026-09-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/pion/dtls/v3","fixedVersion":"3.1.4"}],"fix":{"url":"https://github.com/pion/dtls/pull/839","label":"pion/dtls#839"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54908.json"},{"type":"ADVISORY","url":"https://github.com/pion/dtls/security/advisories/GHSA-wg4g-wm44-ch5j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54908"},{"type":"FIX","url":"https://github.com/pion/dtls/pull/839"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-09T18:26:45.394499423Z"}}