Vulnerability in Dragonfly File Distribution System Exposes OAuth Secrets
CVE-2026-49254
2.9LOW
What is CVE-2026-49254?
Dragonfly, an open-source P2P-based file distribution and image acceleration system, is susceptible to a vulnerability that allows unauthenticated clients to access sensitive OAuth configuration details. Prior to version 2.4.4, the system lacked adequate middleware protection for specific API endpoints, allowing exposure of client secrets, identifiers, and redirect URLs associated with the configured GitHub or Google OAuth providers. Without proper safeguards, an attacker could exploit this oversight to misuse the identity-provider integration. This vulnerability highlights the need for robust security measures in handling OAuth integrations.
Affected Version(s)
dragonfly < 2.4.4
