Linux / Dragonfly
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-24124 | Dragonfly Manager Job API Allows Unauthenticated Access | HIGH | 8.9 | Jan 22, 2026 |
| CVE-2025-59410 | Dragonfly tiny file download uses hard coded HTTP protocol | MEDIUM | 5.5 | Sep 17, 2025 |
| CVE-2025-59354 | Dragonfly has weak integrity checks for downloaded files | MEDIUM | 5.5 | Sep 17, 2025 |
| CVE-2025-59353 | Manager generates mTLS certificates for arbitrary IP addresses | HIGH | 7.7 | Sep 17, 2025 |
| CVE-2025-59352 | Dragonfly allows arbitrary file read and write on a peer machine | MEDIUM | 6.9 | Sep 17, 2025 |
| CVE-2025-59351 | Dragonfly possibly panics due to nil pointer dereference when using variables created alongside an error | MEDIUM | 5.5 | Sep 17, 2025 |
| CVE-2025-59350 | Timing attacks against Proxy’s basic authentication are possible | MEDIUM | 5.5 | Sep 17, 2025 |
| CVE-2025-59349 | Directories created via os.MkdirAll are not checked for permissions | LOW | 2.0 | Sep 17, 2025 |
| CVE-2025-59348 | Dragonfly incorrectly handles a task structure’s usedTraffic field | MEDIUM | 5.5 | Sep 17, 2025 |
| CVE-2025-59347 | Dragonfly Manager makes requests to external endpoints with disabled TLS authentication | MEDIUM | 5.5 | Sep 17, 2025 |
| CVE-2025-59346 | Dragonfly server-side request forgery vulnerability | HIGH | 7.7 | Sep 17, 2025 |
| CVE-2025-59345 | Dragonfly did not enable authentication for some Manager’s endpoints | HIGH | 7.7 | Sep 17, 2025 |
| CVE-2023-27584 | Dragonfly2 vulnerable to hard coded cyptographic key | CRITICAL | 9.3 | Sep 19, 2024 |
Showing 1 to 13 of 13 CVEs