Vulnerability in Dragonfly File Distribution System Exposes OAuth Secrets
CVE-2026-49254

2.9LOW

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-49254?

Dragonfly, an open-source P2P-based file distribution and image acceleration system, is susceptible to a vulnerability that allows unauthenticated clients to access sensitive OAuth configuration details. Prior to version 2.4.4, the system lacked adequate middleware protection for specific API endpoints, allowing exposure of client secrets, identifiers, and redirect URLs associated with the configured GitHub or Google OAuth providers. Without proper safeguards, an attacker could exploit this oversight to misuse the identity-provider integration. This vulnerability highlights the need for robust security measures in handling OAuth integrations.

Affected Version(s)

dragonfly < 2.4.4

References

CVSS V4

Score:
2.9
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.