PT-2025-38262 · Dragonfly · Dragonfly

Gaius-Qi

·

Published

2025-09-17

·

Updated

2025-10-27

·

CVE-2025-59351

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Dragonfly versions prior to 2.1.0
Description Dragonfly is a P2P-based file distribution and image acceleration system. Prior to version 2.1.0, the first return value of a function is dereferenced even when the function returns an error, potentially resulting in a nil dereference and causing the code to panic. This issue was identified in the server.Download method where a malicious actor could cause the system to panic by sending a dfdaemonv1.DownRequest request.
Recommendations Upgrade to version 2.1.0 or later.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-59351
GHSA-4MHV-8RH3-4GHW
GO-2025-3970
OPENSUSE-SU-2025:15576-1
SUSE-SU-2025:3799-1

Affected Products

Dragonfly