d7y.io/dragonfly/v2
Activity
- Latest release
- 4d ago
- Total releases
- 72
- Cadence
- ~10 days
- Last 12 months
- 30
Details
- First release
- Jul 20, 2021
| Version | Released | |
|---|---|---|
v2.5.2
patch
|
v2.5.2
patch
Dependencies (76)
+ 68 more |
|
v2.5.2-rc.4
pre
|
v2.5.2-rc.4
pre
Dependencies (76)
+ 68 more |
|
v2.5.2-rc.3
pre
|
v2.5.2-rc.3
pre
Dependencies (76)
+ 68 more |
|
v2.5.2-rc.2
pre
|
v2.5.2-rc.2
pre
Dependencies (76)
+ 68 more |
|
v2.5.2-rc.1
pre
|
v2.5.2-rc.1
pre
Dependencies (76)
+ 68 more |
|
v2.5.2-rc.0
pre
|
v2.5.2-rc.0
pre
Dependencies (76)
+ 68 more |
|
v2.5.1
patch
|
v2.5.1
patch
Dependencies (79)
+ 71 more |
|
v2.4.4
patch
|
v2.4.4
patch
Dependencies (78)
+ 70 more |
|
v2.5.0
minor
|
v2.5.0
minor
Dependencies (78)
+ 70 more |
|
v2.4.4-rc.4
pre
1 CVE
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev |
v2.4.4-rc.4
pre
Dependencies (78)
+ 70 more |
|
v2.4.4-rc.3
pre
1 CVE
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev |
v2.4.4-rc.3
pre
Dependencies (78)
+ 70 more |
|
v2.4.4-rc.2
pre
2 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev |
v2.4.4-rc.2
pre
Dependencies (78)
+ 70 more |
|
v2.4.4-rc.1
pre
2 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev |
v2.4.4-rc.1
pre
Dependencies (78)
+ 70 more |
|
v2.4.4-rc.0
pre
2 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev |
v2.4.4-rc.0
pre
Dependencies (78)
+ 70 more |
|
v2.4.4-beta.0
pre
2 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev |
v2.4.4-beta.0
pre
Dependencies (78)
+ 70 more |
|
v2.4.3
minor
2 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev |
v2.4.3
minor
Dependencies (77)
+ 69 more |
|
v2.4.2-test
pre
2 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev |
v2.4.2-test
pre
Dependencies (77)
+ 69 more |
|
v2.4.2
patch
2 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev |
v2.4.2
patch
Dependencies (77)
+ 69 more |
|
v2.4.1
patch
2 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev |
v2.4.1
patch
Dependencies (77)
+ 69 more |
|
v2.4.1-rc.1
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.4.1-rc.1
pre
Dependencies (77)
+ 69 more |
|
v2.4.1-rc.0
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.4.1-rc.0
pre
Dependencies (77)
+ 69 more |
|
v2.4.1-beta.1
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.4.1-beta.1
pre
Dependencies (77)
+ 69 more |
|
v2.4.1-beta.0
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.4.1-beta.0
pre
Dependencies (77)
+ 69 more |
|
v2.4.0
minor
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.4.0
minor
Dependencies (77)
+ 69 more |
|
v2.3.5-rc.3
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.5-rc.3
pre
Dependencies (77)
+ 69 more |
|
v2.3.5-rc.2
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.5-rc.2
pre
Dependencies (77)
+ 69 more |
|
v2.3.5-rc.1
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.5-rc.1
pre
Dependencies (77)
+ 69 more |
|
v2.3.5-rc.0
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.5-rc.0
pre
Dependencies (77)
+ 69 more |
|
v2.3.5-beta.1
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.5-beta.1
pre
Dependencies (77)
+ 69 more |
|
v2.3.4-beta.0-test
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.4-beta.0-test
pre
Dependencies (102)
+ 94 more |
|
v2.3.1-beta.1
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.1-beta.1
pre
Dependencies (102)
+ 94 more |
|
v2.2.3
minor
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.3
minor
Dependencies (101)
+ 93 more |
|
v2.2.3-rc.4
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.3-rc.4
pre
Dependencies (101)
+ 93 more |
|
v2.2.3-rc.1
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.3-rc.1
pre
Dependencies (102)
+ 94 more |
|
v2.2.1-rc.0
pre
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.1-rc.0
pre
Dependencies (102)
+ 94 more |
|
v2.1.65
patch
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.65
patch
Dependencies (96)
+ 88 more |
|
v2.1.60
patch
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.60
patch
Dependencies (96)
+ 88 more |
|
v2.1.46
patch
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.46
patch
Dependencies (97)
+ 89 more |
|
v2.1.45
patch
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.45
patch
Dependencies (97)
+ 89 more |
|
v2.1.44
patch
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.44
patch
Dependencies (95)
+ 87 more |
|
v2.1.35
patch
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.35
patch
Dependencies (94)
+ 86 more |
|
v2.1.33
patch
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.33
patch
Dependencies (94)
+ 86 more |
|
v2.0.10
patch
15 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59349
GO-2025-3964
GHSA-8425-8r2f-mrv6
Sep 24, 2025
Dragonfly's directories created via os.MkdirAll are not checked for permissions in d7y.io/dragonfly Dragonfly's directories created via os.MkdirAll are not checked for permissions in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59354
GO-2025-3973
GHSA-hx2h-vjw2-8r54
Sep 24, 2025
DragonFly has weak integrity checks for downloaded files in d7y.io/dragonfly DragonFly has weak integrity checks for downloaded files in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59351
GO-2025-3970
GHSA-4mhv-8rh3-4ghw
Sep 24, 2025
DragonFly vulnerable to panics due to nil pointer dereference when using variables created alongside an error in d7y.io/dragonfly DragonFly vulnerable to panics due to nil pointer dereference when using variables created alongside an error in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59353
GO-2025-3969
GHSA-255v-qv84-29p5
Sep 24, 2025
DragonFly's manager generates mTLS certificates for arbitrary IP addresses in d7y.io/dragonfly DragonFly's manager generates mTLS certificates for arbitrary IP addresses in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59352
GO-2025-3971
GHSA-79hx-3fp8-hj66
Sep 24, 2025
DragonFly vulnerable to arbitrary file read and write on a peer machine in d7y.io/dragonfly DragonFly vulnerable to arbitrary file read and write on a peer machine in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59350
GO-2025-3972
GHSA-c2fc-9q9c-5486
Sep 24, 2025
Dragonfly vulnerable to timing attacks against Proxy’s basic authentication in d7y.io/dragonfly Dragonfly vulnerable to timing attacks against Proxy’s basic authentication in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59348
GO-2025-3963
GHSA-2qgr-gfvj-qpcr
Sep 24, 2025
Dragonfly incorrectly handles a task structure’s usedTrac field in d7y.io/dragonfly Dragonfly incorrectly handles a task structure’s usedTrac field in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59345
GO-2025-3965
GHSA-89vc-vf32-ch59
Sep 24, 2025
Dragonfly doesn't have authentication enabled for some Manager’s endpoints in d7y.io/dragonfly Dragonfly doesn't have authentication enabled for some Manager’s endpoints in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59347
GO-2025-3966
GHSA-98x5-jw98-6c97
Sep 24, 2025
Dragonfly's manager makes requests to external endpoints with disabled TLS authentication in d7y.io/dragonfly Dragonfly's manager makes requests to external endpoints with disabled TLS authentication in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59346
GO-2025-3968
GHSA-g2rq-jv54-wcpr
Sep 24, 2025
Dragonfly vulnerable to server-side request forgery in d7y.io/dragonfly Dragonfly vulnerable to server-side request forgery in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59410
GO-2025-3974
GHSA-mcvp-rpgg-9273
Sep 24, 2025
DragonFly's tiny file download uses hard coded HTTP protocol in d7y.io/dragonfly DragonFly's tiny file download uses hard coded HTTP protocol in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-27584
GO-2024-3136
GHSA-hpc8-7wpm-889w
Sep 26, 2024
Dragonfly2 has hard coded cyptographic key in d7y.io/dragonfly Dragonfly2 has hard coded cyptographic key in d7y.io/dragonfly Fixed in
2.1.0-beta.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.0.10
patch
Dependencies (87)
+ 79 more |
|
v2.1.22
patch
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.22
patch
Dependencies (92)
+ 84 more |
|
v2.1.21
patch
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.21
patch
Dependencies (92)
+ 84 more |
|
v2.1.6
patch
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.6
patch
Dependencies (88)
+ 80 more |
|
v2.1.5
patch
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.5
patch
Dependencies (88)
+ 80 more |
|
v2.1.1
minor
3 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.1
minor
Dependencies (88)
+ 80 more |
|
v2.1.0-alpha.4
pre
15 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59349
GO-2025-3964
GHSA-8425-8r2f-mrv6
Sep 24, 2025
Dragonfly's directories created via os.MkdirAll are not checked for permissions in d7y.io/dragonfly Dragonfly's directories created via os.MkdirAll are not checked for permissions in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59354
GO-2025-3973
GHSA-hx2h-vjw2-8r54
Sep 24, 2025
DragonFly has weak integrity checks for downloaded files in d7y.io/dragonfly DragonFly has weak integrity checks for downloaded files in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59351
GO-2025-3970
GHSA-4mhv-8rh3-4ghw
Sep 24, 2025
DragonFly vulnerable to panics due to nil pointer dereference when using variables created alongside an error in d7y.io/dragonfly DragonFly vulnerable to panics due to nil pointer dereference when using variables created alongside an error in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59353
GO-2025-3969
GHSA-255v-qv84-29p5
Sep 24, 2025
DragonFly's manager generates mTLS certificates for arbitrary IP addresses in d7y.io/dragonfly DragonFly's manager generates mTLS certificates for arbitrary IP addresses in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59352
GO-2025-3971
GHSA-79hx-3fp8-hj66
Sep 24, 2025
DragonFly vulnerable to arbitrary file read and write on a peer machine in d7y.io/dragonfly DragonFly vulnerable to arbitrary file read and write on a peer machine in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59350
GO-2025-3972
GHSA-c2fc-9q9c-5486
Sep 24, 2025
Dragonfly vulnerable to timing attacks against Proxy’s basic authentication in d7y.io/dragonfly Dragonfly vulnerable to timing attacks against Proxy’s basic authentication in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59348
GO-2025-3963
GHSA-2qgr-gfvj-qpcr
Sep 24, 2025
Dragonfly incorrectly handles a task structure’s usedTrac field in d7y.io/dragonfly Dragonfly incorrectly handles a task structure’s usedTrac field in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59345
GO-2025-3965
GHSA-89vc-vf32-ch59
Sep 24, 2025
Dragonfly doesn't have authentication enabled for some Manager’s endpoints in d7y.io/dragonfly Dragonfly doesn't have authentication enabled for some Manager’s endpoints in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59347
GO-2025-3966
GHSA-98x5-jw98-6c97
Sep 24, 2025
Dragonfly's manager makes requests to external endpoints with disabled TLS authentication in d7y.io/dragonfly Dragonfly's manager makes requests to external endpoints with disabled TLS authentication in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59346
GO-2025-3968
GHSA-g2rq-jv54-wcpr
Sep 24, 2025
Dragonfly vulnerable to server-side request forgery in d7y.io/dragonfly Dragonfly vulnerable to server-side request forgery in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59410
GO-2025-3974
GHSA-mcvp-rpgg-9273
Sep 24, 2025
DragonFly's tiny file download uses hard coded HTTP protocol in d7y.io/dragonfly DragonFly's tiny file download uses hard coded HTTP protocol in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-27584
GO-2024-3136
GHSA-hpc8-7wpm-889w
Sep 26, 2024
Dragonfly2 has hard coded cyptographic key in d7y.io/dragonfly Dragonfly2 has hard coded cyptographic key in d7y.io/dragonfly Fixed in
2.1.0-beta.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.0-alpha.4
pre
Dependencies (87)
+ 79 more |
|
v2.0.9
patch
15 CVEs
CVE-2026-49254
GO-2026-5901
GHSA-4q9j-6299-gxmr
Jul 07, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth in d7y.io/dragonfly Fixed in
2.4.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-54637
GO-2026-5910
GHSA-chwm-m7g7-685g
Jul 07, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly Fixed in
2.4.4-rc.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-24124
GO-2026-4356
GHSA-j8hf-cp34-g4j7
Feb 02, 2026
Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Dragonfly Manager Job API Unauthenticated Access in d7y.io/dragonfly Fixed in
2.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59349
GO-2025-3964
GHSA-8425-8r2f-mrv6
Sep 24, 2025
Dragonfly's directories created via os.MkdirAll are not checked for permissions in d7y.io/dragonfly Dragonfly's directories created via os.MkdirAll are not checked for permissions in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59354
GO-2025-3973
GHSA-hx2h-vjw2-8r54
Sep 24, 2025
DragonFly has weak integrity checks for downloaded files in d7y.io/dragonfly DragonFly has weak integrity checks for downloaded files in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59351
GO-2025-3970
GHSA-4mhv-8rh3-4ghw
Sep 24, 2025
DragonFly vulnerable to panics due to nil pointer dereference when using variables created alongside an error in d7y.io/dragonfly DragonFly vulnerable to panics due to nil pointer dereference when using variables created alongside an error in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59353
GO-2025-3969
GHSA-255v-qv84-29p5
Sep 24, 2025
DragonFly's manager generates mTLS certificates for arbitrary IP addresses in d7y.io/dragonfly DragonFly's manager generates mTLS certificates for arbitrary IP addresses in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59352
GO-2025-3971
GHSA-79hx-3fp8-hj66
Sep 24, 2025
DragonFly vulnerable to arbitrary file read and write on a peer machine in d7y.io/dragonfly DragonFly vulnerable to arbitrary file read and write on a peer machine in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59350
GO-2025-3972
GHSA-c2fc-9q9c-5486
Sep 24, 2025
Dragonfly vulnerable to timing attacks against Proxy’s basic authentication in d7y.io/dragonfly Dragonfly vulnerable to timing attacks against Proxy’s basic authentication in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59348
GO-2025-3963
GHSA-2qgr-gfvj-qpcr
Sep 24, 2025
Dragonfly incorrectly handles a task structure’s usedTrac field in d7y.io/dragonfly Dragonfly incorrectly handles a task structure’s usedTrac field in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59345
GO-2025-3965
GHSA-89vc-vf32-ch59
Sep 24, 2025
Dragonfly doesn't have authentication enabled for some Manager’s endpoints in d7y.io/dragonfly Dragonfly doesn't have authentication enabled for some Manager’s endpoints in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59347
GO-2025-3966
GHSA-98x5-jw98-6c97
Sep 24, 2025
Dragonfly's manager makes requests to external endpoints with disabled TLS authentication in d7y.io/dragonfly Dragonfly's manager makes requests to external endpoints with disabled TLS authentication in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59346
GO-2025-3968
GHSA-g2rq-jv54-wcpr
Sep 24, 2025
Dragonfly vulnerable to server-side request forgery in d7y.io/dragonfly Dragonfly vulnerable to server-side request forgery in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-59410
GO-2025-3974
GHSA-mcvp-rpgg-9273
Sep 24, 2025
DragonFly's tiny file download uses hard coded HTTP protocol in d7y.io/dragonfly DragonFly's tiny file download uses hard coded HTTP protocol in d7y.io/dragonfly Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-27584
GO-2024-3136
GHSA-hpc8-7wpm-889w
Sep 26, 2024
Dragonfly2 has hard coded cyptographic key in d7y.io/dragonfly Dragonfly2 has hard coded cyptographic key in d7y.io/dragonfly Fixed in
2.1.0-beta.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.0.9
patch
Dependencies (87)
+ 79 more |