PT-2025-38258 · Dragonfly · Dragonfly

Gaius-Qi

·

Published

2025-09-17

·

Updated

2025-10-27

·

CVE-2025-59347

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Dragonfly versions prior to 2.1.0
Description Dragonfly, an open source P2P-based file distribution and image acceleration system, disables TLS certificate verification in its HTTP clients. These clients are not configurable, preventing users from re-enabling verification. An attacker can perform a Man-in-the-Middle attack, providing invalid data to the Manager, leading to preheating with incorrect data, resulting in denial of service and file integrity issues. The vulnerable code snippet involves the getAuthToken function and the TLSClientConfig within the http.Transport, where InsecureSkipVerify is set to true.
Recommendations Upgrade to version 2.1.0 or later.

Exploit

Fix

Improper Authentication

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2025-59347
GHSA-98X5-JW98-6C97
GO-2025-3966
OPENSUSE-SU-2025:15576-1
SUSE-SU-2025:3799-1

Affected Products

Dragonfly