Dragonfly
27 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Dragonfly, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Dragonfly CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 2 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 11 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 2 |
| 2026-07 | 0 |
| 2026-08 | 1 |
| 2026-09 | 2 |
Severity
How the 27 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical6
- High7
- Medium6
- Low4
Latest CVEs
The 15 most recently published vulnerabilities affecting Dragonfly.
- CVE-2026-49254Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth—
- CVE-2026-54637Dragonfly scheduler v1 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile—
- CVE-2026-62357DragonflyDB `CMS.INITBYDIM` integer overflow leads to a remote, attacker-controlled heap out-of-bounds write—
- CVE-2026-54341Dragonfly: RESTORE operations may crash the server7.5
- CVE-2026-47206Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer—
- CVE-2026-24124Dragonfly Manager Job API Allows Unauthenticated Access9.8
- CVE-2025-59410Dragonfly tiny file download uses hard coded HTTP protocol3.7
- CVE-2025-59354Dragonfly has weak integrity checks for downloaded files5.3
- CVE-2025-59353Manager generates mTLS certificates for arbitrary IP addresses7.5
- CVE-2025-59352Dragonfly allows arbitrary file read and write on a peer machine9.8
- CVE-2025-59351Dragonfly possibly panics due to nil pointer dereference when using variables created alongside an error5.3
- CVE-2025-59350Timing attacks against Proxy’s basic authentication are possible5.3
- CVE-2025-59349Directories created via os.MkdirAll are not checked for permissions3.3
- CVE-2025-59348Dragonfly incorrectly handles a task structure’s usedTraffic field7.5
- CVE-2025-59347Dragonfly Manager makes requests to external endpoints with disabled TLS authentication6.5
Product grouping is registry-driven, with AI assist and human review. How it works