PT-2025-38274 · Dragonfly · Dragonfly

Gaius-Qi

·

Published

2025-09-17

·

Updated

2025-10-27

·

CVE-2025-59410

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Dragonfly versions prior to 2.1.0
Description Dragonfly, an open source P2P-based file distribution and image acceleration system, is susceptible to a Man-in-the-Middle attack. The scheduler for downloading small files was configured to use the HTTP protocol instead of HTTPS. This allows an attacker to intercept and modify network requests, potentially replacing legitimate data with malicious content. The vulnerability is exacerbated by weak integrity checks. The vulnerable code segment is located within the DownloadTinyFile() function. The target URL used in the vulnerable function is: http://${host}:${port}/download/${taskIndex}/${taskID}?peerId=${peerID}.
Recommendations Upgrade to Dragonfly version 2.1.0 or later.

Exploit

Fix

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2025-59410
GHSA-MCVP-RPGG-9273
GO-2025-3974
OPENSUSE-SU-2025:15576-1
SUSE-SU-2025:3799-1

Affected Products

Dragonfly