Executive brief
Hysteria is a network proxy tool used to optimize and secure internet connections. A vulnerability allows an authenticated user to crash the Hysteria server by sending specially crafted network settings. This results in a denial-of-service, making the proxy service unavailable to all users until it is manually restarted.
Technical details
A slice bounds panic exists in the Hysteria server's UDP fragmentation logic. When an authenticated client advertises a very small QUIC 'max_datagram_frame_size', the server's 'sendMessageAutoFrag' function attempts to fragment UDP responses. The 'FragUDPMessage' function in 'core/internal/frag/frag.go' fails to account for cases where the maximum allowed payload size is smaller than the UDP message header itself. This leads to a negative or zero 'maxPayloadSize' calculation, causing a runtime panic and immediate termination of the server process. The issue is fixed in version 2.9.2.
Affected products
- apernet hysteria < 2.9.2
Timeline
- 2026-05-23: disclosed
- 2026-06-26: advisory
- 2026-06-26: patched: Fixed in version 2.9.2