CRITICAL 9.4 NVD
CVE-2026-55181
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts the OIDC login flow, returns HTTP 302, sets an oidc_state cookie, and redirects the user to the configured OIDC authorization endpoint. This bypasses the intended OIDC disable switch. This issue has been patched in version 1.30.3.
References
- https://github.com/Quenary/tugtainer/commit/76371db679334b002d4af544b0f3b8587ad86f52
- https://github.com/Quenary/tugtainer/releases/tag/v1.30.3
- https://github.com/Quenary/tugtainer/security/advisories/GHSA-rg7c-vpfp-2w43
- https://github.com/Quenary/tugtainer/security/advisories/GHSA-rg7c-vpfp-2w43
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-09-30 via NVD.
Risk Timeline
CVE Disclosed2026-09-30 · -1 days ago
Remediation Resources
vulnfeed aggregates 9504 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.