Dragonfly
Vendor:
First CVE: Sep 19, 2024 · Active for 1 year
13
Total CVEs
More Total CVEs than 91% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dragonfly over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 19, 2024
22 months ago
Most Recent CVE
Jan 22, 2026
183 days ago
CVE Severity & Scoring
Dragonfly13 CVEs
15%
38%
15%
31%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (7.7%)
Network12 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (84.6%)
High2 (15.4%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (7.7%)
High0 (0.0%)
None12 (92.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27584CRITICAL Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. | Sep 19, 2024 | 9.8 | 61 | NO | YES |
CVE-2026-24124CRITICAL Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authenticatio | Jan 22, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-59352CRITICAL Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send requests that force the recipi | Sep 17, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-59345CRITICAL Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Manager web UI are accessible wit | Sep 17, 2025 | 9.1 | 27 | NO | NO |
CVE-2025-59353HIGH Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for arbitrary IP addresses, effecti | Sep 17, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-59348HIGH Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceFromSource method does not update the structure’s usedTraffic | Sep 17, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-59347MEDIUM Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verification in HTTP clients. The client | Sep 17, 2025 | 6.5 | 21 | NO | NO |
CVE-2025-59354MEDIUM Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash functions, including the MD5 hash, for | Sep 17, 2025 | 5.3 | 19 | NO | NO |
CVE-2025-59351MEDIUM Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return value of a function is dereferenced even when the function r | Sep 17, 2025 | 5.3 | 19 | NO | NO |
CVE-2025-59350MEDIUM Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the access control mechanism for the Proxy feature uses simple string compari | Sep 17, 2025 | 5.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
7.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Dragonfly
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.4.1 | 1 | 9.8 | 0.7% | 0 | 0 |