CVE-2026-24124

CRITICAL

Dragonfly <2.4.1-rc.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authentication middleware and RBAC authorization checks in the routing configuration. This allows any unauthenticated user with access to the Manager API to view, update and delete jobs. The issue is fixed in version 2.4.1-rc.1.

Scores

CVSS v3 9.8
EPSS 0.0071
EPSS Percentile 48.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (3)
dragonfly/v2 0 - 2.4.1Go
linuxfoundation/dragonfly 2.4.1 beta0 (3 CPE variants)
linuxfoundation/dragonfly < 2.4.1
Published Jan 22, 2026
Tracked Since Feb 18, 2026