Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

dragonfly — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in dragonfly, with AI-generated Chinese analysis, references, and POCs.

This page documents the Common Weakness Enumeration (CWE) vulnerabilities associated with the Dragonfly product developed by its respective vendor. It serves as a centralized repository for tracking security flaws, configuration errors, and software weaknesses affecting this specific application. The content aggregates vulnerability data spanning from early 2021 to mid-2024, providing a comprehensive view of the product’s security landscape over this period. The collection includes diverse vulnerability types such as remote code execution, cross-site scripting, and insecure default configurations. By consolidating these records, the page offers a detailed chronological account of reported issues, patches, and advisory notices. Users can utilize this resource to systematically track the vendor’s official advisories and monitor the progression of security updates for Dragonfly. It allows developers and security analysts to understand the specific characteristics of prevalent weakness classes within this software ecosystem. Additionally, the archive enables users to look up the complete vulnerability history of Dragonfly, facilitating better risk assessment and compliance auditing. This structured approach helps stakeholders identify recurring security patterns and evaluate the effectiveness of mitigation strategies implemented over time. The information is presented to support informed decision-making regarding product deployment and ongoing maintenance without promotional language or introductory filler.

Vendor: HyperaDev

CVE IDTitleCVSSSeverityPublished
CVE-2026-54341 Dragonfly: RESTORE operations may crash the server CWE-125 7.5 High2026-06-26
CVE-2026-47206 Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer CWE-116--2026-06-26
CVE-2026-24124 Dragonfly Manager Job API Allows Unauthenticated Access CWE-306 9.8 -2026-01-22
CVE-2025-59410 Dragonfly tiny file download uses hard coded HTTP protocol CWE-311 5.9AIMediumAI2025-09-17
CVE-2025-59354 Dragonfly has weak integrity checks for downloaded files CWE-328 6.5AIMediumAI2025-09-17
CVE-2025-59353 Manager generates mTLS certificates for arbitrary IP addresses CWE-295 6.5AIMediumAI2025-09-17
CVE-2025-59352 Dragonfly allows arbitrary file read and write on a peer machine CWE-202 8.8AIHighAI2025-09-17
CVE-2025-59351 Dragonfly possibly panics due to nil pointer dereference when using variables created alongside an error CWE-476 7.5AIHighAI2025-09-17
CVE-2025-59350 Timing attacks against Proxy’s basic authentication are possible CWE-208 5.9AIMediumAI2025-09-17
CVE-2025-59349 Directories created via os.MkdirAll are not checked for permissions CWE-732 3.3AILowAI2025-09-17
CVE-2025-59348 Dragonfly incorrectly handles a task structure’s usedTraffic field CWE-457 7.5AIHighAI2025-09-17
CVE-2025-59347 Dragonfly Manager makes requests to external endpoints with disabled TLS authentication CWE-295 7.4AIHighAI2025-09-17
CVE-2025-59346 Dragonfly server-side request forgery vulnerability CWE-918 4.6AIMediumAI2025-09-17
CVE-2025-59345 Dragonfly did not enable authentication for some Manager’s endpoints CWE-306 9.1AICriticalAI2025-09-17
CVE-2025-52935 Integer Overflow or Wraparound vulnerability in dragonflydb/dragonfly CWE-190 8.4AIHighAI2025-06-23
CVE-2025-26268 Dragonfly 安全漏洞 CWE-392 3.3 Low2025-04-17
CVE-2025-26269 Dragonfly 安全漏洞 CWE-191 3.3 Low2025-04-17
CVE-2022-41967 Improper Restriction of XML External Entity Reference in Dragonfly CWE-611 7.0 High2022-12-27

All 18 known CVE vulnerabilities affecting dragonfly with full Chinese analysis, references, and POCs where available.