Vulnerabilidades em pion
7 resultadosAnálise Vexday
Pion apresenta 6 vulnerabilidades registradas, com apenas 1 publicada nos últimos 90 dias, indicando risco moderado e estável. Nenhuma vulnerabilidade está sob ataque ativo ou classificada como crítica, reduzindo a urgência imediata. A fraqueza dominante é CWE-120 (buffer overflow), típica de componentes legados, recomendando atenção na gestão de atualizações e testes de integração.
CVE-2022-29189MEDIUMBuffer for inbound DTLS fragments has no limitEPSS 2.1%CVE-2022-29190HIGHHeader reconstruction method can be thrown into an infinite loop in Pion DTLSEPSS 1.7%CVE-2022-29222MEDIUMImproper Certificate Validation in Pion DTLSEPSS 0.8%CVE-2026-26014MEDIUMPion DTLS uses random nonce generation with AES GCM ciphers risks leaking the authentication keyEPSS 0.6%CVE-2026-54908MEDIUMPion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange messageEPSS 0.5%CVE-2025-49140HIGHPion Interceptor's improper RTP padding handling allows remote crash for SFU users (DoS)EPSS 0.5%CVE-2026-54909MEDIUMPion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attributeEPSS 0.4%