← Vulnerability feed

Vulnerability record · CVE-2025-59353 · published 17 September 2025

CVE-2025-59353: Linuxfoundation dragonfly improper certificate validation vulnerability

Linuxfoundation · Dragonfly

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for arbitrary IP addresses, effectively rendering the mTLS authentication useless. The issue is that the Manager’s Certificate gRPC service does not validate if the requested IP addresses “belong to” the peer requesting the certificate—that is, if the peer connects from the same IP address as the one provided in the certificate request. This vulnerability is fixed in 2.1.0.

7.7 CVSS 4.0 High EPSS 0.23% · top 87.3% CWE-295 · Improper certificate validationCWE-862 · Missing authorization
7.7CVSS 4.0 base score
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for arbitrary IP addresses, effectively rendering the mTLS authentication useless. The issue is that the Manager’s Certificate gRPC service does not validate if the requested IP addresses “belong to” the peer requesting the certificate—that is, if the peer connects from the same IP address as the one provided in the certificate request. This vulnerability is fixed in 2.1.0.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59353 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27584Linuxfoundation dragonfly hard-coded credentials vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) a…EPSS 34%8.9CVE-2026-24124Linuxfoundation dragonfly missing authentication for critical function vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/…EPSS 0.79%7.7CVE-2025-59345Linuxfoundation dragonfly missing authentication for critical function vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Ma…EPSS 0.38%6.9CVE-2025-59352Linuxfoundation dragonfly path traversal vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send…EPSS 0.73%5.5CVE-2025-59354Linuxfoundation dragonfly vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash function…EPSS 0.16%5.5CVE-2025-59410Linuxfoundation dragonfly missing encryption vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a ti…EPSS 0.14%5.5CVE-2025-59348Linuxfoundation dragonfly vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceFromSource method does not upd…EPSS 0.36%5.5CVE-2025-59346Linuxfoundation dragonfly server-side request forgery (ssrf) vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery …EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2025-59353), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.