VendorsLinux Foundationdragonflyany version
Vulnerabilities

Linux Foundation Dragonfly any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2023-27584
Dragonfly2 vulnerable to hard coded cyptographic key
Published 2024-09-19 · Analyzed
9.8EPSS 0.336
CVE-2026-24124
Dragonfly Manager Job API Allows Unauthenticated Access
Published 2026-01-22 · Analyzed
9.8EPSS 0.008
CVE-2025-59352
Dragonfly allows arbitrary file read and write on a peer machine
Published 2025-09-17 · Analyzed
9.8EPSS 0.007
CVE-2025-59345
Dragonfly did not enable authentication for some Manager’s endpoints
Published 2025-09-17 · Modified
9.1EPSS 0.004
CVE-2025-59353
Manager generates mTLS certificates for arbitrary IP addresses
Published 2025-09-17 · Analyzed
7.7EPSS 0.002
CVE-2025-59348
Dragonfly incorrectly handles a task structure’s usedTraffic field
Published 2025-09-17 · Analyzed
7.5EPSS 0.004
CVE-2025-59347
Dragonfly Manager makes requests to external endpoints with disabled TLS authentication
Published 2025-09-17 · Analyzed
6.5EPSS 0.002
CVE-2025-59346
Dragonfly server-side request forgery vulnerability
Published 2025-09-17 · Analyzed
5.5EPSS 0.002
CVE-2025-59354
Dragonfly has weak integrity checks for downloaded files
Published 2025-09-17 · Analyzed
5.5EPSS 0.002
CVE-2025-59410
Dragonfly tiny file download uses hard coded HTTP protocol
Published 2025-09-17 · Analyzed
5.5EPSS 0.001
CVE-2025-59350
Timing attacks against Proxy’s basic authentication are possible
Published 2025-09-17 · Analyzed
5.3EPSS 0.003
CVE-2025-59351
Dragonfly possibly panics due to nil pointer dereference when using variables created alongside an error
Published 2025-09-17 · Analyzed
5.3EPSS 0.003
CVE-2025-59349
Directories created via os.MkdirAll are not checked for permissions
Published 2025-09-17 · Analyzed
3.3EPSS 0.001