icon

We found results for “

CVE-2025-59350

Good to know:

icon

Date: September 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the access control mechanism for the Proxy feature uses simple string comparisons and is therefore vulnerable to timing attacks. An attacker may try to guess the password one character at a time by sending all possible characters to a vulnerable mechanism and measuring the comparison instruction’s execution times. This vulnerability is fixed in 2.1.0.

Severity Score

Severity Score

Weakness Type (CWE)

Observable Timing Discrepancy

CWE-208

Incorrect Comparison

CWE-697

Top Fix

icon

Upgrade Version

Upgrade to version github.com/dragonflyoss/dragonfly - v2.1.0;d7y.io/dragonfly/v2 - v2.1.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us