Critical severity9.8NVD Advisory· Published Apr 19, 2020· Updated Jun 17, 2026
CVE-2019-20786
CVE-2019-20786
Description
handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows remote attackers to inject arbitrary unencrypted data after handshake completion.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/pion/dtlsGo | < 1.5.2 | 1.5.2 |
Affected products
2- Pion/Pion DTLSdescription
Patches
Vulnerability mechanics
References
8- github.com/pion/dtls/commit/fd73a5df2ff0e1fb6ae6a51e2777d7a16cc4f4e0nvdPatchThird Party AdvisoryWEB
- github.com/pion/dtls/compare/v1.5.1...v1.5.2nvdPatchThird Party AdvisoryWEB
- www.usenix.org/system/files/sec20fall_fiterau-brostean_prepub.pdfnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-7gfg-6934-mqq2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-20786ghsaADVISORY
- www.usenix.org/conference/usenixsecurity20/presentation/fiterau-brosteannvdThird Party AdvisoryWEB
- github.com/pion/dtls/pull/128ghsaWEB
- pkg.go.dev/vuln/GO-2020-0038ghsaWEB
News mentions
0No linked articles in our index yet.