Junglewise Threat Intelligence

apernet Hysteria server crash via small max_datagram_frame_size

Severity: high · CVSS 7.5 · Published 2026-06-26

Technologies: github.com/apernet/hysteria (Go), Apernet Hysteria. Vendors: Go, Apernet.

Executive brief

Hysteria is a network proxy tool used to optimize and secure internet connections. A vulnerability allows an authenticated user to crash the Hysteria server by sending specially crafted network settings. This results in a denial-of-service, making the proxy service unavailable to all users until it is manually restarted.

Technical details

A slice bounds panic exists in the Hysteria server's UDP fragmentation logic. When an authenticated client advertises a very small QUIC 'max_datagram_frame_size', the server's 'sendMessageAutoFrag' function attempts to fragment UDP responses. The 'FragUDPMessage' function in 'core/internal/frag/frag.go' fails to account for cases where the maximum allowed payload size is smaller than the UDP message header itself. This leads to a negative or zero 'maxPayloadSize' calculation, causing a runtime panic and immediate termination of the server process. The issue is fixed in version 2.9.2.

Affected products

  • apernet hysteria < 2.9.2

Timeline

  • 2026-05-23: disclosed
  • 2026-06-26: advisory
  • 2026-06-26: patched: Fixed in version 2.9.2

References

Related threats