The 329-file repository carries a full client and server
Our checkout contained 329 files, about 41,330 lines of source, and occupied 15.8 MB. Hysteria itself is written in Go and ships client and server modes in the same executable. Its documented client modes include SOCKS5, HTTP proxy, TCP and UDP forwarding, TUN, and several transparent-routing options. The repository also has a Dockerfile, a written protocol specification, and 8 CI workflow files.
The design makes one large bet: customized QUIC over UDP can behave better than conventional proxy traffic on unreliable or filtered paths. Hysteria can make its server answer like an HTTP/3 site, and it can obfuscate traffic when a network targets QUIC patterns. Those are project claims, not findings from our sandbox. Whether they hold for you depends on the mobile carrier, office firewall, national filter, NAT, and MTU between each client and server.
What happened when we ran it
Our sandbox installed commit 47138dc in 7 seconds, adding 35 packages and using 38 MB on disk. The measurement setup was an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Python 3.12, and no secrets. The repository's Python project describes those dependencies as build-script and test helpers for Hysteria. Pip-audit found 0 known vulnerabilities in that installed Python environment.
The recorded build step succeeded in 0 seconds. That result needs a plain reading: the lab runner found no substantive build target to execute, so it did not prove that the Go client and server compiled. The runner also found no test script or target and skipped tests. Go test files are present in the source tree, but our run produced no test count or pass result. We did not start a server, send traffic, or measure throughput, latency, loss, reconnection, or filtering behavior.
Port 443 needs UDP, TLS, authentication, and a believable endpoint
The basic server listens on UDP port 443, using either ACME or certificate and key files. Its setup guide asks for a public IP address and a domain pointing to it, though Hysteria Realms offers a NAT traversal route when no public IP is available. Authentication can be a shared password. Binding 443 may require root or the narrower cap_net_bind_service capability.
Masquerading is part of the censorship-resistance story. The starter configuration reverse-proxies an ordinary website so an HTTP request receives plausible content rather than exposing an obvious dead endpoint. Operators who do not need that behavior can remove the section and return 404 responses. Either way, the server is security-sensitive infrastructure: choose the upstream content, protect the password, renew the certificate, restrict management access, and check what the service exposes before placing it on a public address.
UDP on port 443 is the deciding network requirement
Hysteria 2 currently documents UDP as its only transport type. The client can use BBR, Reno, or the project's Brutal congestion controller, with configured bandwidth selecting Brutal for that direction. The guide warns that an inflated bandwidth value can cause congestion and unstable connections. This is a tool for paths where UDP works well enough to carry QUIC. A network that drops UDP entirely ends the evaluation early.
Path details matter even when UDP passes. Open issue 1656 describes an Android LTE route with a 1,300-byte MTU where an oversized QUIC initial packet never left the device, while the client surfaced only a generic timeout. That report concerns one reproduced configuration and does not prove a universal mobile defect. It does show why a successful desktop connection is weak evidence for phones, tunnels, and carriers with different MTUs.
Version 2.13.0 keeps several modes tied to Linux
Hysteria v2.13.0 covers more than a local SOCKS5 listener, but mode availability differs by operating system. TProxy, transparent TCP redirect, fake TCP, and server-side port-range listening are Linux-specific in the documentation. Port hopping can require nftables or iptables plus root or CAP_NET_ADMIN. The Docker example uses host networking and adds NET_ADMIN when port hopping is enabled.
TLS deserves equal care. A client may trust a private CA or use a pinned SHA-256 fingerprint with verification disabled. The guide explicitly warns against using insecure by itself because that permits a man-in-the-middle attack. Share links can contain the server password and settings, which makes the URI a credential. Treat it like one in chat logs, screenshots, ticket systems, and shell history.
22,619 stars and a same-day release show active maintenance
GitHub listed 22,619 stars and 260 open issues and pull requests on October 5, 2026. The repository was pushed that day, and app/v2.13.0 was released the same day. That release fixed QUIC protocol sniffing when modern clients split ClientHello across packets, updated the TUN dependency, removed an ineffective route.strict option, and updated its QUIC library. The dates and the specific network fixes show current work rather than a project resting on an old tag.
Current activity does not remove failure modes. Open issue 1682 reports that a client on v2.12.2 can wait forever when a server accepts a TCP stream but never answers while keeping the QUIC connection alive. The reporter observed recovery only after restarting the client and proposed a bounded read. Version 2.13.0's release notes do not list that issue as fixed, and it remained open when checked. Long-running client deployments should test this case and supervise the process.
The 7-second install leaves the hard question unanswered
Hysteria 2 is worth a trial when the network path itself is the enemy and you control both ends. Its modes, protocol documentation, current release work, and cross-platform binaries make that trial practical. Our 7-second helper install and 0-vulnerability Python audit say the repository's small support environment is easy to reproduce. They say nothing about the proxy's defining promise. Put a client on the actual carrier or filtered network, test UDP failure and low MTU, then decide whether Hysteria beats a broader proxy core for that route.

