PT-2025-38254 · Dragonfly · Dragonfly

Gaius-Qi

·

Published

2025-09-17

·

Updated

2025-10-27

·

CVE-2025-59346

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions Dragonfly versions prior to 2.1.0
Description Dragonfly is a P2P-based file distribution and image acceleration system susceptible to a server-side request forgery (SSRF) vulnerability. This flaw allows users to force Dragonfly2’s components to make requests to internal services that are otherwise inaccessible. The issue stems from weak validation of user-supplied URLs when creating Preheat jobs via the Manager API, the pieceManager.DownloadSource method in peer-to-peer communication, and HTTP clients following redirects. This can lead to probing or access of internal HTTP endpoints.
Recommendations Upgrade to version 2.1.0 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-59346
GHSA-G2RQ-JV54-WCPR
GO-2025-3968
OPENSUSE-SU-2025:15576-1
SUSE-SU-2025:3799-1

Affected Products

Dragonfly