CVE-2025-59410
- EPSS 0.02%
- Veröffentlicht 17.09.2025 19:58:54
- Zuletzt bearbeitet 18.09.2025 16:54:11
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a tiny file is hard coded to use the HTTP protocol, rather than HTTPS. This means that an attacker could ...
CVE-2025-59354
- EPSS 0.02%
- Veröffentlicht 17.09.2025 19:57:07
- Zuletzt bearbeitet 18.09.2025 20:08:13
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash functions, including the MD5 hash, for downloaded files. This allows attackers to replace files with maliciou...
CVE-2025-59353
- EPSS 0.05%
- Veröffentlicht 17.09.2025 19:53:36
- Zuletzt bearbeitet 18.09.2025 20:08:55
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for arbitrary IP addresses, effectively rendering the mTLS authentication useless. The issue is that the ...
CVE-2025-59352
- EPSS 0.64%
- Veröffentlicht 17.09.2025 19:50:38
- Zuletzt bearbeitet 18.09.2025 20:09:03
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send requests that force the recipient peer to create files in arbitrary file system locations, and to re...
CVE-2025-59351
- EPSS 0.05%
- Veröffentlicht 17.09.2025 19:46:41
- Zuletzt bearbeitet 18.09.2025 20:09:21
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return value of a function is dereferenced even when the function returns an error. This can result in a nil dereference, and cause code ...
CVE-2025-59350
- EPSS 0.07%
- Veröffentlicht 17.09.2025 19:43:24
- Zuletzt bearbeitet 18.09.2025 20:15:45
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the access control mechanism for the Proxy feature uses simple string comparisons and is therefore vulnerable to timing attacks. An attacker may tr...
CVE-2025-59349
- EPSS 0.02%
- Veröffentlicht 17.09.2025 19:41:03
- Zuletzt bearbeitet 18.09.2025 20:17:51
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, DragonFly2 uses the os.MkdirAll function to create certain directory paths with specific access permissions. This function does not perform any per...
CVE-2025-59348
- EPSS 0.06%
- Veröffentlicht 17.09.2025 19:30:22
- Zuletzt bearbeitet 18.09.2025 20:18:46
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceFromSource method does not update the structure’s usedTraffic field, because an uninitialized variable n is used as a guard to the ...
CVE-2025-59347
- EPSS 0.04%
- Veröffentlicht 17.09.2025 19:23:20
- Zuletzt bearbeitet 18.09.2025 20:19:08
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verification in HTTP clients. The clients are not configurable, so users have no way to re-enable the verifica...
CVE-2025-59346
- EPSS 0.04%
- Veröffentlicht 17.09.2025 19:20:23
- Zuletzt bearbeitet 18.09.2025 20:20:38
Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery (SSRF) vulnerability that enables users to force DragonFly2’s components to make requests to internal...