d7y.io/dragonfly/v2
Go12 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting d7y.io/dragonfly/v2page 1 of 1
- CVE-2023-27584CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.1.0-beta.12024-09-19
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key …
- CVE-2025-59345CRITICALCVSS 9.1EG 9.1✓ Fixed in 2.1.02025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Manager web UI are accessible without authentication. Any user with network access to the Ma…
- CVE-2025-59346MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.1.02025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery (SSRF) vulnerability that enables users to force DragonFly2’s components to make request…
- CVE-2025-59347MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.1.02025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verification in HTTP clients. The clients are not configurable, so users have no way to re-enable t…
- CVE-2025-59348HIGHCVSS 7.5EG 7.5✓ Fixed in 2.1.02025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceFromSource method does not update the structure’s usedTraffic field, because an uninitialized variable n is used as a …
- CVE-2025-59350MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.1.02025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the access control mechanism for the Proxy feature uses simple string comparisons and is therefore vulnerable to timing attacks. An atta…
- CVE-2025-59351MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.1.02025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return value of a function is dereferenced even when the function returns an error. This can result in a nil dereference, and …
- CVE-2025-59352CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.1.02025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send requests that force the recipient peer to create files in arbitrary file system locations…
- CVE-2025-59353HIGHCVSS 7.5EG 7.5✓ Fixed in 2.1.02025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for arbitrary IP addresses, effectively rendering the mTLS authentication useless. The issue i…
- CVE-2025-59354MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.1.02025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash functions, including the MD5 hash, for downloaded files. This allows attackers to replace files wi…
- CVE-2025-59410LOWCVSS 3.7EG 3.7✓ Fixed in 2.1.02025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a tiny file is hard coded to use the HTTP protocol, rather than HTTPS. This means that an atta…
- CVE-2026-24124CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.4.12026-01-22
Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authentication middleware and RBAC authorization checks in the routing c…
Check whether d7y.io/dragonfly/v2 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for d7y.io/dragonfly/v2 CVEs against the assets you own.
Start Free Scan →