PT-2026-7719 · Pion Dtls · Pion Dtls

Theodorsm

·

Publicado

2026-02-11

·

Atualizado

2026-03-03

·

CVE-2026-26014

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pion DTLS versions 1.0.0 through 3.1.0
Description Pion DTLS, a Go implementation of Datagram Transport Layer Security, is susceptible to an issue where the use of random nonce generation with AES GCM ciphers allows remote attackers to potentially obtain the authentication key and spoof data. This is possible due to nonce reuse in a session and a “forbidden attack”.
Recommendations Upgrade to version 3.1.0 or later. This version includes a fix that uses the 64-bit sequence number to populate the nonce explicit part of the GCM nonce. There are no workarounds without upgrading to version 3.1.0 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-77645
AZL-77649
CVE-2026-26014
GHSA-9F3F-WV7R-QC8R
GO-2026-4479
SUSE-SU-2026:0757-1

Produtos afetados

Pion Dtls