I'm not particularly knowledgeable about the verification process being done by 
dnf on the signature of packages so the question still lies on me:
Is downloading packages from plaintext http susceptible to MITM?

Even if that is not the case, I believe we can't be for sure that there's no 
exploitable vulnerability on dnf involving packages poisoned either from the 
source itself or in transit through plaintext http.

