← Vulnerability feed

Vulnerability record · CVE-2025-59345 · published 17 September 2025

CVE-2025-59345: Linuxfoundation dragonfly missing authentication for critical function vulnerability

Linuxfoundation · Dragonfly

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Manager web UI are accessible without authentication. Any user with network access to the Manager can create, delete, and modify jobs, and create preheat jobs. An unauthenticated adversary with network access to a Manager web UI uses /api/v1/jobs endpoint to create hundreds of useless jobs. The Manager is in a denial-of-service state, and stops accepting requests from valid administrators. This vulnerability is fixed in 2.1.0.

7.7 CVSS 4.0 High EPSS 0.38% · top 70.2% CWE-306 · Missing authentication for critical function
7.7CVSS 4.0 base score
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Manager web UI are accessible without authentication. Any user with network access to the Manager can create, delete, and modify jobs, and create preheat jobs. An unauthenticated adversary with network access to a Manager web UI uses /api/v1/jobs endpoint to create hundreds of useless jobs. The Manager is in a denial-of-service state, and stops accepting requests from valid administrators. This vulnerability is fixed in 2.1.0.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59345 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27584Linuxfoundation dragonfly hard-coded credentials vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) a…EPSS 34%8.9CVE-2026-24124Linuxfoundation dragonfly missing authentication for critical function vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/…EPSS 0.79%7.7CVE-2025-59353Linuxfoundation dragonfly improper certificate validation vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for …EPSS 0.23%6.9CVE-2025-59352Linuxfoundation dragonfly path traversal vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send…EPSS 0.73%5.5CVE-2025-59354Linuxfoundation dragonfly vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash function…EPSS 0.16%5.5CVE-2025-59410Linuxfoundation dragonfly missing encryption vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a ti…EPSS 0.14%5.5CVE-2025-59348Linuxfoundation dragonfly vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceFromSource method does not upd…EPSS 0.36%5.5CVE-2025-59346Linuxfoundation dragonfly server-side request forgery (ssrf) vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery …EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2025-59345), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.