Executive brief
Dragonfly incorrectly handles a task structure’s usedTrac field in d7y.io/dragonfly
Affected products
- Go github.com/dragonflyoss/dragonfly
- Go d7y.io/dragonfly/v2
Junglewise Threat Intelligence
CVE-2025-59348 · Severity: medium · CVSS 4 · Published 2025-09-24
Technologies: github.com/dragonflyoss/dragonfly (Go), d7y.io/dragonfly/v2 (Go). Vendors: Go.
Dragonfly incorrectly handles a task structure’s usedTrac field in d7y.io/dragonfly