—
GO-2026-5910
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly
Quick fix
GO-2026-5910 — d7y.io/dragonfly/v2: upgrade to the fixed version with the command below.
go get d7y.io/dragonfly/v2@v2.4.4-rc.3Details
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile in d7y.io/dragonfly
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-chwm-m7g7-685g[ADVISORY]
- https://github.com/dragonflyoss/Dragonfly2/blob/main/scheduler/resource/standard/peer.go#L457-L459[WEB]
- https://github.com/dragonflyoss/dragonfly/blob/0822e3aecc3369017d6b25c9441ff6f318129b31/internal/job/image.go#L211[WEB]
- https://github.com/dragonflyoss/dragonfly/blob/0822e3aecc3369017d6b25c9441ff6f318129b31/pkg/net/http/http.go#L50-L80[WEB]
- https://github.com/dragonflyoss/dragonfly/blob/0822e3aecc3369017d6b25c9441ff6f318129b31/pkg/rpc/scheduler/server/server.go#L71-L90[WEB]
- https://github.com/dragonflyoss/dragonfly/blob/0822e3aecc3369017d6b25c9441ff6f318129b31/scheduler/resource/standard/peer.go#L435-L478[WEB]
- https://github.com/dragonflyoss/dragonfly/blob/0822e3aecc3369017d6b25c9441ff6f318129b31/scheduler/scheduler.go#L235-L246[WEB]
- https://github.com/dragonflyoss/dragonfly/blob/0822e3aecc3369017d6b25c9441ff6f318129b31/scheduler/service/service_v1.go#L1176-L1202[WEB]
- https://github.com/dragonflyoss/dragonfly/blob/0822e3aecc3369017d6b25c9441ff6f318129b31/scheduler/service/service_v1.go#L816-L845[WEB]
- https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-fhf9-m53m-863g[WEB]