CVE-2025-59410

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a tiny file is hard coded to use the HTTP protocol, rather than HTTPS. This means that an attacker could perform a Man-in-the-Middle attack, changing the network request so that a different piece of data gets downloaded. This vulnerability is fixed in 2.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:linuxfoundation:dragonfly:*:*:*:*:*:go:*:*

History

17 Jun 2026, 09:46

Type Values Removed Values Added
Summary
  • (es) Dragonfly es un sistema de distribución de archivos y aceleración de imágenes de código abierto basado en P2P. Antes de la 2.1.0, el código en el planificador para descargar un archivo pequeño está codificado de forma rígida para usar el protocolo HTTP, en lugar de HTTPS. Esto significa que un atacante podría realizar un ataque Man-in-the-Middle, cambiando la solicitud de red para que se descargue una pieza de datos diferente. Esta vulnerabilidad está corregida en la 2.1.0.

18 Sep 2025, 16:54

Type Values Removed Values Added
CPE cpe:2.3:a:linuxfoundation:dragonfly:*:*:*:*:*:go:*:*
First Time Linuxfoundation
Linuxfoundation dragonfly
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.7
References () https://github.com/dragonflyoss/dragonfly/blob/main/docs/security/dragonfly-comprehensive-report-2023.pdf - () https://github.com/dragonflyoss/dragonfly/blob/main/docs/security/dragonfly-comprehensive-report-2023.pdf - Product
References () https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-mcvp-rpgg-9273 - () https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-mcvp-rpgg-9273 - Patch, Third Party Advisory

17 Sep 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-17 20:15

Updated : 2026-06-17 09:46


NVD link : CVE-2025-59410

Mitre link : CVE-2025-59410

CVE.ORG link : CVE-2025-59410


JSON object : View

Products Affected

linuxfoundation

  • dragonfly
CWE
CWE-311

Missing Encryption of Sensitive Data