Description
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/router.go registers GET /api/v1/oauth and GET /api/v1/oauth/:id without jwt.MiddlewareFunc() or RBAC(), while manager/handlers/oauth.go returns models.Oauth records and manager/models/oauth.go exposes Oauth.ClientSecret as client_secret in JSON. When an administrator has configured a GitHub or Google OAuth provider, an unauthenticated network client can reach GetOauth or GetOauths, load the stored models.Oauth record, and obtain the provider's client secret, client identifier, and redirect URL. The earlier GHSA-j8hf-cp34-g4j7 remediation protected the /jobs group only and did not protect these OAuth GET handlers. Disclosure of client_secret can enable abuse of the configured identity-provider integration, subject to the provider's redirect URI restrictions. This issue is fixed in 2.4.4.
Published: 2026-09-15
Score: 2.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of OAuth client credentials
Action: Apply Patch
AI Analysis

Impact

Dragonfly is an open‑source P2P‑based file distribution and image acceleration system. The vulnerability existed before version 2.4.4 in the manager/router module, where GET /api/v1/oauth and GET /api/v1/oauth/:id were registered without jwt.MiddlewareFunc() or RBAC() protection. The handler returned full OAuth records, and the model exposed the client_secret field as client_secret in JSON. When an administrator has configured a GitHub or Google OAuth provider, any unauthenticated network client could request these endpoints, retrieve the provider’s client secret, client identifier, and redirect URL. Disclosure of client_secret enables attackers to abuse the configured identity‑provider integration, subject to the provider’s redirect URI restrictions, resulting in a confidentiality breach and classification as CWE‑200, with the missing authentication requirement corresponding to CWE‑306.

Affected Systems

The vulnerability affects Dragonfly releases prior to version 2.4.4. The affected component is the manager/router under dragonflyoss:dragonfly. Administrators who have configured external OAuth providers are the ones impacted, as the insecure API exposes their Provider secrets. The feature was part of the OAuth functionality that could be utilized by any network client that can reach the manager service.

Risk and Exploitability

The CVSS score is 2.9, indicating low severity. The EPSS score is less than 1% and the issue is not listed in CISA’s KEV catalog, suggesting limited publicly known exploitation. The attack vector is straightforward: an unauthenticated HTTP GET request to the managed service, requiring network access to the Dragonfly manager. While the disclosure could allow abuse of OAuth integrations, practical exploitation may be constrained by provider‑side redirect URI restrictions. Nonetheless, the best defense remains to update to version 2.4.4 or later.

Generated by OpenCVE AI on September 17, 2026 at 15:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Dragonfly Manager to version 2.4.4 or a newer release that fixes the unauthenticated access issue.
  • If an upgrade cannot be performed immediately, block external access to /api/v1/oauth and /api/v1/oauth/:id using a firewall or reverse‑proxy rule so that only trusted hosts can reach them.
  • Bind the Dragonfly manager service to internal interfaces or localhost to prevent unauthenticated external hosts from reaching it.

Generated by OpenCVE AI on September 17, 2026 at 15:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4q9j-6299-gxmr Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth
History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Dragonflyoss
Dragonflyoss dragonfly2
Vendors & Products Dragonflyoss
Dragonflyoss dragonfly2

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/router.go registers GET /api/v1/oauth and GET /api/v1/oauth/:id without jwt.MiddlewareFunc() or RBAC(), while manager/handlers/oauth.go returns models.Oauth records and manager/models/oauth.go exposes Oauth.ClientSecret as client_secret in JSON. When an administrator has configured a GitHub or Google OAuth provider, an unauthenticated network client can reach GetOauth or GetOauths, load the stored models.Oauth record, and obtain the provider's client secret, client identifier, and redirect URL. The earlier GHSA-j8hf-cp34-g4j7 remediation protected the /jobs group only and did not protect these OAuth GET handlers. Disclosure of client_secret can enable abuse of the configured identity-provider integration, subject to the provider's redirect URI restrictions. This issue is fixed in 2.4.4.
Title Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth
Weaknesses CWE-200
CWE-306
References
Metrics cvssV4_0

{'score': 2.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Dragonflyoss Dragonfly2
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T18:03:27.313Z

Reserved: 2026-05-28T14:33:01.179Z

Link: CVE-2026-49254

cve-icon Vulnrichment

Updated: 2026-09-15T17:38:30.704Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:16.577

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-49254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T15:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-306

    Missing Authentication for Critical Function