{"id":"GO-2026-6165","summary":"Panic while parsing crafted ECDHE_PSK ServerKeyExchange in github.com/pion/dtls/v3","details":"In github.com/pion/dtls/v3 before 3.1.4, MessageServerKeyExchange.Unmarshal does not verify that data remains after parsing the PSK identity hint when handling ECDHE_PSK key exchange messages. A remote peer sending a crafted ServerKeyExchange message where the PSK hint consumes all remaining data triggers an index out of range runtime panic, causing a denial of service.","aliases":["CVE-2026-54908","GHSA-wg4g-wm44-ch5j"],"modified":"2026-08-18T17:15:27.922773065Z","published":"2026-08-18T16:38:10Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6165"},"references":[{"type":"ADVISORY","url":"https://github.com/pion/dtls/security/advisories/GHSA-wg4g-wm44-ch5j"},{"type":"FIX","url":"https://github.com/pion/dtls/pull/839"},{"type":"FIX","url":"https://github.com/pion/dtls/commit/49458d604a4f3ebce1bf9587a0f3e5f3f6b4a55e"},{"type":"WEB","url":"https://github.com/pion/dtls/releases/tag/v3.1.4"}],"affected":[{"package":{"name":"github.com/pion/dtls/v3","ecosystem":"Go","purl":"pkg:golang/github.com/pion/dtls/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.1.4"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/pion/dtls/v3/pkg/protocol/handshake","symbols":["Handshake.Unmarshal","MessageServerKeyExchange.Unmarshal"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6165.json"}}],"schema_version":"1.9.0","credits":[{"name":"Karolina Gorna"}]}