PT-2025-38259 · Dragonfly · Dragonfly

Gaius-Qi

·

Published

2025-09-17

·

Updated

2025-10-27

·

CVE-2025-59348

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Dragonfly versions prior to 2.1.0
Description The processPieceFromSource method in Dragonfly does not correctly update the usedTraffic field within the Task structure due to the use of an uninitialized variable (n) instead of result.Size when calling the AddTraffic method. This incorrect rate limiting can lead to a denial-of-service condition for the peer processing the task.
Recommendations Upgrade to Dragonfly version 2.1.0 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-59348
GHSA-2QGR-GFVJ-QPCR
GO-2025-3963
OPENSUSE-SU-2025:15576-1
SUSE-SU-2025:3799-1

Affected Products

Dragonfly