CVE-2026-26014

EUVD-2026-6169
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.0.10 and 3.1.0 use random nonce generation with AES GCM ciphers, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a "forbidden attack". Upgrade to v3.0.11, v3.1.1, or later.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 47.04%
Affected Products (NVD)
VendorProductVersion
piondtls
𝑥
< 3.1.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-github-pion-dtls-v3
forky
3.1.5-1
fixed
sid
3.1.5-1
fixed
golang-github-pion-dtls.v2
bookworm
no-dsa
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-github-pion-dtls.v2
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage
golang-github-pion-dtls-v3
jammy
dne
noble
dne
questing
dne
resolute
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
telegraf
Azure Linux 3.0
0:1.31.0-15.azl3
fixed
CBL-Mariner 2.0
0:1.29.4-21.cm2
fixed