Please refer to the community security policy.
Security: dragonflyoss/dragonfly
Security
SECURITY.md
-
Possible panics due to nil pointer dereference when using variables created alongside an errorGHSA-4mhv-8rh3-4ghw published
Sep 17, 2025 by gaius-qiModerate -
Timing attacks against Proxy’s basic authentication are possibleGHSA-c2fc-9q9c-5486 published
Sep 17, 2025 by gaius-qiLow -
Files are closed without error checkGHSA-x3vj-c8hw-4g7f published
Sep 17, 2025 by gaius-qiLow -
Slicing operations with hard-coded indexes and without explicit length validationGHSA-6mwx-ch8x-496q published
Sep 17, 2025 by gaius-qiLow -
Directories created via os.MkdirAll are not checked for permissionsGHSA-8425-8r2f-mrv6 published
Sep 17, 2025 by gaius-qiLow -
Incorrect handling of a task structure’s usedTra�c fieldGHSA-2qgr-gfvj-qpcr published
Sep 17, 2025 by gaius-qiLow -
Manager makes requests to external endpoints with disabled TLS authenticationGHSA-98x5-jw98-6c97 published
Sep 17, 2025 by gaius-qiLow -
Server-side request forgery vulnerabilitiesGHSA-g2rq-jv54-wcpr published
Sep 17, 2025 by gaius-qiModerate -
Authentication is not enabled for some Manager’s endpointsGHSA-89vc-vf32-ch59 published
Sep 17, 2025 by gaius-qiLow -
Critical vulnerability as part of Alpine 3.20 base imageGHSA-2g78-chqr-h5wr published
Sep 10, 2025 by gaius-qiCritical
Learn more about advisories related to dragonflyoss/dragonfly in the GitHub Advisory Database