Please refer to the community security policy.
Security: dragonflyoss/dragonfly
Security
SECURITY.md
-
Manager makes requests to external endpoints with disabled TLS authenticationGHSA-98x5-jw98-6c97 published
Sep 17, 2025 by gaius-qiLow -
Server-side request forgery vulnerabilitiesGHSA-g2rq-jv54-wcpr published
Sep 17, 2025 by gaius-qiModerate -
Authentication is not enabled for some Manager’s endpointsGHSA-89vc-vf32-ch59 published
Sep 17, 2025 by gaius-qiLow -
Critical vulnerability as part of Alpine 3.20 base imageGHSA-2g78-chqr-h5wr published
Sep 10, 2025 by gaius-qiCritical -
Dragonfly2 vulnerable to hard coded cyptographic keyGHSA-hpc8-7wpm-889w published
Sep 19, 2024 by gaius-qiCritical
Learn more about advisories related to dragonflyoss/dragonfly in the GitHub Advisory Database