Hypera Dragonfly
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Hypera Dragonfly.
By the Year
In 2026 there have been 0 vulnerabilities in Hypera Dragonfly. Dragonfly did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 1 | 7.50 |
It may take a day or so for new Dragonfly vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Hypera Dragonfly Security Vulnerabilities
Dragonfly 0.3.0-SNAPSHOT XXE via DocumentBuilderFactory (before 0.3.1)
CVE-2022-41967
7.5 - High
- December 28, 2022
Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderFactory to prevent XML external entity (XXE) attacks. This issue is patched in 0.3.1-SNAPSHOT. As a workaround, since Dragonfly only parses XML `SNAPSHOT` versions are being resolved, this vulnerability may be avoided by not trying to resolve `SNAPSHOT` versions.
XXE
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Hypera Dragonfly or by Hypera? Click the Watch button to subscribe.