# CVE-2025-59410

## Summary

- **CVE ID:** CVE-2025-59410
- **Severity:** MEDIUM
- **CVSS Score:** 5.5 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-311
- **Published:** Sep 17, 2025
- **Last Modified:** Mar 13, 2026

## Description

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a tiny file is hard coded to use the HTTP protocol, rather than HTTPS. This means that an attacker could perform a Man-in-the-Middle attack, changing the network request so that a different piece of data gets downloaded. This vulnerability is fixed in 2.1.0.

## Affected Products

- dragonflyoss — dragonfly (< 2.1.0)

## References

- [CNA](https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-mcvp-rpgg-9273)
- [CNA](https://github.com/dragonflyoss/dragonfly/blob/main/docs/security/dragonfly-comprehensive-report-2023.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 3.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._