CVE-2026-26014 is a medium-severity vulnerability affecting Pion DTLS versions v1.0.0 through v3.0.10 and v3.1.0, a Go implementation of Datagram Transport Layer Security. The flaw stems from insecure random nonce generation with AES GCM ciphers, allowing remote attackers to potentially obtain authentication keys and spoof data through nonce reuse within a session. While the attack complexity is high, successful exploitation could lead to significant confidentiality impacts. There is no evidence of active exploitation, and no public exploit code is available; however, it has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.0CPE matchmatch criteria | cpe:2.3:a:pion:dtls:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.