Skip to main content

Vendor/product archive

linuxfoundation / dragonfly CVEs

Beta · best-effort

13 CVEs tagged to linuxfoundation / dragonfly1 Critical, 3 High, 5 Medium, 4 Low, 0 Unrated.

CVE-2026-24124

Published Jan 22, 2026

Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authenticati…

CVSS 8.9 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-59410

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a tiny file is hard coded to use t…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59354

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash functions, including the MD5 hash, for…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59353

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for arbitrary IP addresses, effect…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59352

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send requests that force the recip…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59351

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return value of a function is dereferenced even when the function…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-59350

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the access control mechanism for the Proxy feature uses simple string compar…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-59349

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, DragonFly2 uses the os.MkdirAll function to create certain directory paths w…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-59348

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceFromSource method does not update the structure’s usedTraffi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59347

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verification in HTTP clients. The clien…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-59346

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery (SSRF) vulnerability that enab…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59345

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Manager web UI are accessible wi…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27584

Published Sep 19, 2024

Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1