Dragonflyoss
11 CVEs tracked since 2025. Since Sep 2025, none of them reached CISA KEV.
Dragonflyoss CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-09 | 11 | 0 |
Products
The products that kept showing up in Dragonflyoss's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Dragonflyoss.
- CVE-2026-49254Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth—
- CVE-2026-54637Dragonfly scheduler v1 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile—
- CVE-2026-24124Dragonfly Manager Job API Allows Unauthenticated Access9.8
- CVE-2025-59410Dragonfly tiny file download uses hard coded HTTP protocol3.7
- CVE-2025-59354Dragonfly has weak integrity checks for downloaded files5.3
- CVE-2025-59353Manager generates mTLS certificates for arbitrary IP addresses7.5
- CVE-2025-59352Dragonfly allows arbitrary file read and write on a peer machine9.8
- CVE-2025-59351Dragonfly possibly panics due to nil pointer dereference when using variables created alongside an error5.3
- CVE-2025-59350Timing attacks against Proxy’s basic authentication are possible5.3
- CVE-2025-59349Directories created via os.MkdirAll are not checked for permissions3.3
- CVE-2025-59348Dragonfly incorrectly handles a task structure’s usedTraffic field7.5
- CVE-2025-59347Dragonfly Manager makes requests to external endpoints with disabled TLS authentication6.5
- CVE-2025-59346Dragonfly server-side request forgery vulnerability5.3
- CVE-2025-59345Dragonfly did not enable authentication for some Manager’s endpoints9.1
- CVE-2023-27584Dragonfly2 vulnerable to hard coded cyptographic key9.8
The record
- Peak rank
- #64 in Sep 2025
- Busiest month shown
- Sep 2025, 11 CVEs
- Months with a KEV entry
- 0 since Sep 2025
- Monthly snapshots
- 1 since 2025