Pion is a WebRTC framework focused on peer-to-peer communication, with a notably narrow but strategically important footprint centered on DTLS (Datagram Transport Layer Security) implementation. Observed vulnerabilities cluster around classic memory-safety issues such as buffer overflows, coupled with authentication, certificate validation, and sensitive information disclosure concerns that reflect the cryptographic and protocol-parsing demands of real-time media transport. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pion over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20786CRITICAL handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows remote attackers to inject arbitrary unencrypted data after | Apr 19, 2020 | 9.8 | 31 | NO | NO |
CVE-2022-29190HIGH Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, an attacker can send packets that sends Pion DTLS into an infinite loop when processi | May 21, 2022 | 7.5 | 25 | NO | NO |
CVE-2026-26014MEDIUM Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.0.10 and 3.1.0 use random nonce generation with AES GCM ciphers, which m | Feb 11, 2026 | 5.9 | 22 | NO | NO |
CVE-2022-29189MEDIUM Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, a buffer that was used for inbound network traffic had no upper limit. Pion DTLS woul | May 21, 2022 | 5.3 | 21 | NO | NO |
CVE-2022-29222HIGH Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.5, a DTLS Client could provide a Certificate that it doesn't posses the private key for | May 21, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pion.
Media articles that mention a CVE ID that affects a product developed by Pion — matched by CVE ID, not by vendor name.