mrkeyoor.com_
Mon 05 Oct 07:12 UTC
Self-Hostedevaluationupdated 05 Oct 2026

hysteria review

Hysteria 2 is a self-hosted proxy that carries traffic through a customized QUIC protocol over UDP. It pairs a server with clients that can expose SOCKS5, HTTP proxy, forwarding, TUN, and Linux transparent-proxy modes for networks where ordinary connections are unreliable or filtered.

Verdict

Our Hysteria run installed 35 Python helper packages in 7 seconds, but it ran no proxy traffic or test suite, so the lab result confirms a tidy helper environment rather than the speed claim that defines the project. Use Hysteria 2 when poor network paths are the problem and you can test UDP, MTU, roaming, and failure recovery yourself. Choose a broader proxy platform if you need several transport families or cannot depend on UDP.

We ran it

Lab card: what happened when we ran hysteriaScreenshot of hysteria (hysteria.network)
Install✓ · 7s35 packages · 38 MB
Build✓ · 0s
Testsn/ano test script
Known vulns0(pip-audit)
Repo329 files~41,330 lines of source · 15.8 MB · 8 CI workflows · Dockerfile

Answers from our run

Does hysteria build from source?

Dependencies installed in 7 seconds (35 packages), and the build succeeded in 0s. We cloned commit 47138dc into a clean Debian container with 3 CPUs and no project-specific setup.

Does hysteria have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does hysteria have known vulnerabilities in its dependencies?

pip-audit found none in the dependency tree at the time of our run.

Who should not use hysteria?

Networks that block UDP outright: the full client configuration lists UDP as the only current transport type.

What are the alternatives to hysteria?

sing-box, Xray-core, TUIC. Our Hysteria run installed 35 Python helper packages in 7 seconds, but it ran no proxy traffic or test suite, so the lab result confirms a tidy helper environment rather than the speed claim that defines the project.

Setup3/57-second helper install, while service needs TLS, UDP, and routing
Docs5/5Detailed client, server, mode, TLS, and protocol documentation
Community5/522,619 stars and an October 5, 2026 release
Maturity4/5v2.13.0 is active, with specific network edge cases still open

Who it’s for

Network engineers who can test QUIC and UDP behavior on the exact paths their users take.
Self-hosters who need SOCKS5, HTTP proxy, TCP or UDP forwarding, or TUN from one client.
Operators comfortable managing a domain, TLS certificates, authentication, firewall rules, and a public server.
Developers who want an MIT-licensed Go implementation with a written protocol specification.

Who it’s NOT for

Networks that block UDP outright: the full client configuration lists UDP as the only current transport type.
Buyers looking for independently measured speed or censorship resistance: our sandbox did not run proxy traffic, latency checks, or packet-loss tests.
Operators who plan to disable TLS verification without pinning the certificate: the client guide warns that this permits man-in-the-middle attacks.
Teams that need every mode on every operating system: TProxy, transparent redirect, fake TCP, and server-side port hopping have Linux-specific limits.
Unattended clients that cannot tolerate a manual restart after a stuck request: open issue 1682 reports a TCP response path that can wait indefinitely while the QUIC connection remains alive.

Setup reality

Our sandbox installed commit 47138dc in 7 seconds, pulling 35 Python helper packages and using 38 MB. The recorded build step succeeded in 0 seconds. No test script or target was available, so tests were skipped. Pip-audit reported 0 known vulnerabilities in the installed Python environment.

A basic server needs a reachable UDP address, a domain, a TLS certificate from ACME or local files, and an authentication password. The client needs the server address, matching authentication, and a local proxy or TUN mode. No hosted API key is required.

Port 443 may need cap_net_bind_service or root. TUN, TProxy, port hopping, and firewall changes need more operating-system access, including NET_ADMIN in the documented Docker example when port hopping is enabled. Networks that discard UDP cannot carry Hysteria's current transport.

The 329-file repository carries a full client and server

Our checkout contained 329 files, about 41,330 lines of source, and occupied 15.8 MB. Hysteria itself is written in Go and ships client and server modes in the same executable. Its documented client modes include SOCKS5, HTTP proxy, TCP and UDP forwarding, TUN, and several transparent-routing options. The repository also has a Dockerfile, a written protocol specification, and 8 CI workflow files.

The design makes one large bet: customized QUIC over UDP can behave better than conventional proxy traffic on unreliable or filtered paths. Hysteria can make its server answer like an HTTP/3 site, and it can obfuscate traffic when a network targets QUIC patterns. Those are project claims, not findings from our sandbox. Whether they hold for you depends on the mobile carrier, office firewall, national filter, NAT, and MTU between each client and server.

What happened when we ran it

Our sandbox installed commit 47138dc in 7 seconds, adding 35 packages and using 38 MB on disk. The measurement setup was an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Python 3.12, and no secrets. The repository's Python project describes those dependencies as build-script and test helpers for Hysteria. Pip-audit found 0 known vulnerabilities in that installed Python environment.

The recorded build step succeeded in 0 seconds. That result needs a plain reading: the lab runner found no substantive build target to execute, so it did not prove that the Go client and server compiled. The runner also found no test script or target and skipped tests. Go test files are present in the source tree, but our run produced no test count or pass result. We did not start a server, send traffic, or measure throughput, latency, loss, reconnection, or filtering behavior.

Port 443 needs UDP, TLS, authentication, and a believable endpoint

The basic server listens on UDP port 443, using either ACME or certificate and key files. Its setup guide asks for a public IP address and a domain pointing to it, though Hysteria Realms offers a NAT traversal route when no public IP is available. Authentication can be a shared password. Binding 443 may require root or the narrower cap_net_bind_service capability.

Masquerading is part of the censorship-resistance story. The starter configuration reverse-proxies an ordinary website so an HTTP request receives plausible content rather than exposing an obvious dead endpoint. Operators who do not need that behavior can remove the section and return 404 responses. Either way, the server is security-sensitive infrastructure: choose the upstream content, protect the password, renew the certificate, restrict management access, and check what the service exposes before placing it on a public address.

UDP on port 443 is the deciding network requirement

Hysteria 2 currently documents UDP as its only transport type. The client can use BBR, Reno, or the project's Brutal congestion controller, with configured bandwidth selecting Brutal for that direction. The guide warns that an inflated bandwidth value can cause congestion and unstable connections. This is a tool for paths where UDP works well enough to carry QUIC. A network that drops UDP entirely ends the evaluation early.

Path details matter even when UDP passes. Open issue 1656 describes an Android LTE route with a 1,300-byte MTU where an oversized QUIC initial packet never left the device, while the client surfaced only a generic timeout. That report concerns one reproduced configuration and does not prove a universal mobile defect. It does show why a successful desktop connection is weak evidence for phones, tunnels, and carriers with different MTUs.

Version 2.13.0 keeps several modes tied to Linux

Hysteria v2.13.0 covers more than a local SOCKS5 listener, but mode availability differs by operating system. TProxy, transparent TCP redirect, fake TCP, and server-side port-range listening are Linux-specific in the documentation. Port hopping can require nftables or iptables plus root or CAP_NET_ADMIN. The Docker example uses host networking and adds NET_ADMIN when port hopping is enabled.

TLS deserves equal care. A client may trust a private CA or use a pinned SHA-256 fingerprint with verification disabled. The guide explicitly warns against using insecure by itself because that permits a man-in-the-middle attack. Share links can contain the server password and settings, which makes the URI a credential. Treat it like one in chat logs, screenshots, ticket systems, and shell history.

22,619 stars and a same-day release show active maintenance

GitHub listed 22,619 stars and 260 open issues and pull requests on October 5, 2026. The repository was pushed that day, and app/v2.13.0 was released the same day. That release fixed QUIC protocol sniffing when modern clients split ClientHello across packets, updated the TUN dependency, removed an ineffective route.strict option, and updated its QUIC library. The dates and the specific network fixes show current work rather than a project resting on an old tag.

Current activity does not remove failure modes. Open issue 1682 reports that a client on v2.12.2 can wait forever when a server accepts a TCP stream but never answers while keeping the QUIC connection alive. The reporter observed recovery only after restarting the client and proposed a bounded read. Version 2.13.0's release notes do not list that issue as fixed, and it remained open when checked. Long-running client deployments should test this case and supervise the process.

The 7-second install leaves the hard question unanswered

Hysteria 2 is worth a trial when the network path itself is the enemy and you control both ends. Its modes, protocol documentation, current release work, and cross-platform binaries make that trial practical. Our 7-second helper install and 0-vulnerability Python audit say the repository's small support environment is easy to reproduce. They say nothing about the proxy's defining promise. Put a client on the actual carrier or filtered network, test UDP failure and low MTU, then decide whether Hysteria beats a broader proxy core for that route.

Alternatives

ProjectWhat it isPick it when
sing-box gh↗A universal proxy platform that supports several inbound, outbound, and routing choices.pick this instead when one multi-protocol client and routing layer matters more than Hysteria's focused protocol.
Xray-core gh↗A configurable proxy core built around multiple transports and protocols.pick this instead when your deployment needs a broader protocol matrix and you accept a larger configuration surface.
TUICA QUIC-based proxy protocol and implementation with a narrower feature set.pick this instead when you want to compare another QUIC proxy before committing clients and servers to Hysteria 2.

What people are saying

  1. [velocity-scout] HyNetworks/hysteria

Sources

  1. Hysteria repository and README
  2. Hysteria 2 installation guide
  3. Hysteria 2 server setup guide
  4. Hysteria 2 client setup guide
  5. Hysteria 2 full client configuration
  6. Hysteria app v2.13.0 release
  7. Hysteria issue 1682: unbounded TCP response wait
  8. Hysteria issue 1656: hidden MTU send failure

More self-hosted reviews

skillbox · vm2api · FounderOS-DEMO · UFI-TOOLS · awesome-cloudflare-selfhosted · life · the whole board →