Junglewise Threat Intelligence

apernet Hysteria UDP ACL bypass and SSRF

Severity: high · CVSS 7.4 · Published 2026-06-26

Technologies: github.com/apernet/hysteria/core/v2 (Go), Apernet Hysteria. Vendors: Apernet, Go.

Executive brief

Hysteria, a popular network proxy, contains a vulnerability where its security rules for UDP traffic can be bypassed by authenticated users. An attacker can establish a legitimate connection and then reuse that session to send data to restricted internal locations, such as the server's own local services or private corporate network. This could lead to unauthorized access to internal DNS resolvers, management tools, or other private infrastructure.

Technical details

Hysteria's UDP relay implementation incorrectly caches Access Control List (ACL) and outbound policy evaluations at the session level rather than the packet level. While the Hysteria protocol allows each UDP message within a session to specify a different destination address, the server only performs ACL validation on the first packet of a session. Subsequent packets in the same session are forwarded using 'e.conn.WriteTo' without re-running policy checks. An authenticated attacker can exploit this by initiating a session to a permitted destination and then sending subsequent packets to restricted destinations like 127.0.0.1 or RFC1918 addresses. This results in a Server-Side Request Forgery (SSRF) that bypasses operator-configured egress restrictions. The issue is fixed in version 2.9.2.

Affected products

  • apernet hysteria/core/v2 >= 2.0.0, <= 2.9.1

Timeline

  • 2026-05-23: disclosed
  • 2026-06-26: advisory
  • 2026-06-26: patched: Fixed in version 2.9.2

References

Related threats