Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Dragonfly — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in Dragonfly, with AI-generated Chinese analysis, references, and POCs.

This page aggregates publicly disclosed security vulnerabilities for Dragonfly, a popular container image distribution system developed by DragonflyCloud. It collects recent advisories and known defects reported across the Dragonfly ecosystem, covering updates and fixes released over the past three years. Readers can use this hub to track the vendor’s security patches, review the frequency and severity of reported flaws, and understand the broader weakness classes affecting this container registry infrastructure.

Vendor: HyperaDev

CVE ID Title CVSS Severity Published
CVE-2026-49254 Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth CWE-200 2.9 Low 2026-09-15
CVE-2026-54637 Dragonfly scheduler v1 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile CWE-918 5.5 Medium 2026-09-15
CVE-2026-62357 DragonflyDB `CMS.INITBYDIM` integer overflow leads to a remote, attacker-controlled heap out-of-bounds write CWE-190 8.8 High 2026-08-18
CVE-2026-54341 Dragonfly: RESTORE operations may crash the server CWE-125 7.5 High 2026-06-26
CVE-2026-47206 Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer CWE-116 - - 2026-06-26
CVE-2026-24124 Dragonfly Manager Job API Allows Unauthenticated Access CWE-306 9.8 - 2026-01-22
CVE-2025-59410 Dragonfly tiny file download uses hard coded HTTP protocol CWE-311 5.9AI Medium AI 2025-09-17
CVE-2025-59354 Dragonfly has weak integrity checks for downloaded files CWE-328 6.5AI Medium AI 2025-09-17
CVE-2025-59353 Manager generates mTLS certificates for arbitrary IP addresses CWE-295 6.5AI Medium AI 2025-09-17
CVE-2025-59352 Dragonfly allows arbitrary file read and write on a peer machine CWE-202 8.8AI High AI 2025-09-17
CVE-2025-59351 Dragonfly possibly panics due to nil pointer dereference when using variables created alongside an error CWE-476 7.5AI High AI 2025-09-17
CVE-2025-59350 Timing attacks against Proxy’s basic authentication are possible CWE-208 5.9AI Medium AI 2025-09-17
CVE-2025-59349 Directories created via os.MkdirAll are not checked for permissions CWE-732 3.3AI Low AI 2025-09-17
CVE-2025-59348 Dragonfly incorrectly handles a task structure’s usedTraffic field CWE-457 7.5AI High AI 2025-09-17
CVE-2025-59347 Dragonfly Manager makes requests to external endpoints with disabled TLS authentication CWE-295 7.4AI High AI 2025-09-17
CVE-2025-59346 Dragonfly server-side request forgery vulnerability CWE-918 4.6AI Medium AI 2025-09-17
CVE-2025-59345 Dragonfly did not enable authentication for some Manager’s endpoints CWE-306 9.1AI Critical AI 2025-09-17
CVE-2025-52935 Integer Overflow or Wraparound vulnerability in dragonflydb/dragonfly CWE-190 8.4AI High AI 2025-06-23
CVE-2025-26268 Dragonfly 安全漏洞 CWE-392 3.3 Low 2025-04-17
CVE-2025-26269 Dragonfly 安全漏洞 CWE-191 3.3 Low 2025-04-17
CVE-2022-41967 Improper Restriction of XML External Entity Reference in Dragonfly CWE-611 7.0 High 2022-12-27

All 21 known CVE vulnerabilities affecting Dragonfly with full Chinese analysis, references, and POCs where available.