CVE-2025-59351: Linuxfoundation Dragonfly

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return value of a function is dereferenced even when the function returns an error. This can result in a nil dereference, and cause code to panic. This vulnerability is fixed in 2.1.0.

Affected products

Published 2025-09-17. Last modified 2026-06-17.