CRITICAL 9.1 NVD
CVE-2026-62308
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This can be abused as an authenticated blind server-side request forgery (SSRF). This issue has been patched in version 1.30.6.
References
- https://github.com/Quenary/tugtainer/commit/c0294d0ab64985b135d0c5b566ac30bf8371f9c3
- https://github.com/Quenary/tugtainer/releases/tag/v1.30.6
- https://github.com/Quenary/tugtainer/security/advisories/GHSA-c2h5-ppv9-7vrq
- https://github.com/Quenary/tugtainer/security/advisories/GHSA-c2h5-ppv9-7vrq
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-09-30 via NVD.
Risk Timeline
CVE Disclosed2026-09-30 · -1 days ago
Remediation Resources
vulnfeed aggregates 9504 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.