dragonfly vulnerabilities
CVEs whose affected-version data names the dragonfly package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-54637Medium· 5.5PoCDragonfly is an open source P2P-based file distribution and image acceleration system
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the scheduler's default unauthenticated v1 gRPC flow accepts attacker-controlled PeerHost.Ip and PeerHost.DownPort values through…
▾ Twilightdragonflyoss · dragonflyEPSS 0.49%via NVD
CVE-2026-49254Low· 2.9Dragonfly is an open source P2P-based file distribution and image acceleration system
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/router.go registers GET /api/v1/oauth and GET /api/v1/oauth/:id without jwt.MiddlewareFunc() or RBAC(), while manager/h…
▾ Sunlitdragonflyoss · dragonflyEPSS 0.28%via NVD