← Vulnerability feed

Vulnerability record · CVE-2025-59354 · published 17 September 2025

CVE-2025-59354: Linuxfoundation dragonfly vulnerability

Linuxfoundation · Dragonfly

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash functions, including the MD5 hash, for downloaded files. This allows attackers to replace files with malicious ones that have a colliding hash. This vulnerability is fixed in 2.1.0.

5.5 CVSS 4.0 Medium EPSS 0.16% · top 95.1% CWE-328 · CWE-328
5.5CVSS 4.0 base score
0.16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash functions, including the MD5 hash, for downloaded files. This allows attackers to replace files with malicious ones that have a colliding hash. This vulnerability is fixed in 2.1.0.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59354 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27584Linuxfoundation dragonfly hard-coded credentials vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) a…EPSS 34%8.9CVE-2026-24124Linuxfoundation dragonfly missing authentication for critical function vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/…EPSS 0.79%7.7CVE-2025-59353Linuxfoundation dragonfly improper certificate validation vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for …EPSS 0.23%7.7CVE-2025-59345Linuxfoundation dragonfly missing authentication for critical function vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Ma…EPSS 0.38%6.9CVE-2025-59352Linuxfoundation dragonfly path traversal vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send…EPSS 0.73%5.5CVE-2025-59410Linuxfoundation dragonfly missing encryption vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a ti…EPSS 0.14%5.5CVE-2025-59348Linuxfoundation dragonfly vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceFromSource method does not upd…EPSS 0.36%5.5CVE-2025-59346Linuxfoundation dragonfly server-side request forgery (ssrf) vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery …EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2025-59354), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.