SSRF Vulnerability in Dragonfly by DragonflyOSS
CVE-2026-54637
5.5MEDIUM
What is CVE-2026-54637?
Dragonfly, an open-source P2P-based file distribution and image acceleration system, possesses a vulnerability in its gRPC flow, wherein the default settings allow unauthorized input for crucial parameters like PeerHost.Ip and PeerHost.DownPort. This security flaw permits a remote attacker to exploit the system, leading to unauthorized access to sensitive endpoints within internal networks. Specifically, attackers can craft requests that probe loopback and private services by leveraging downloaded files, risking the exposure of internal resources. Mitigation measures implemented in versions post 2.4.4-rc.3 prevent access to loopback and link-local targets, while still permitting connections to private ranges.
Affected Version(s)
dragonfly < 2.4.4-rc.3
