CVE-2025-59351

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return value of a function is dereferenced even when the function returns an error. This can result in a nil dereference, and cause code to panic. This vulnerability is fixed in 2.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:linuxfoundation:dragonfly:*:*:*:*:*:go:*:*

History

17 Jun 2026, 09:45

Type Values Removed Values Added
Summary
  • (es) Dragonfly es un sistema de distribución de archivos y aceleración de imágenes de código abierto basado en P2P. Antes de la 2.1.0, el primer valor de retorno de una función es desreferenciado incluso cuando la función devuelve un error. Esto puede resultar en una desreferenciación nula y provocar un pánico en el código. Esta vulnerabilidad se corrigió en la 2.1.0.

18 Sep 2025, 20:09

Type Values Removed Values Added
First Time Linuxfoundation
Linuxfoundation dragonfly
CPE cpe:2.3:a:linuxfoundation:dragonfly:*:*:*:*:*:go:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References () https://github.com/dragonflyoss/dragonfly/blob/main/docs/security/dragonfly-comprehensive-report-2023.pdf - () https://github.com/dragonflyoss/dragonfly/blob/main/docs/security/dragonfly-comprehensive-report-2023.pdf - Product
References () https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-4mhv-8rh3-4ghw - () https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-4mhv-8rh3-4ghw - Patch, Third Party Advisory

17 Sep 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-17 20:15

Updated : 2026-06-17 09:45


NVD link : CVE-2025-59351

Mitre link : CVE-2025-59351

CVE.ORG link : CVE-2025-59351


JSON object : View

Products Affected

linuxfoundation

  • dragonfly
CWE
CWE-476

NULL Pointer Dereference