Finsys Dockhand vulnerabilities
2 known vulnerabilities affecting finsys/dockhand.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-53988P2CRITICALCVSS 10.0fixed in 1.0.402026-09-29
CVE-2026-53988 [CRITICAL] CWE-306 CVE-2026-53988: Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints
Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker c
nvd
CVE-2026-53989P4MEDIUMCVSS 4.7fixed in 1.0.362026-09-29
CVE-2026-53989 [MEDIUM] CWE-601 CVE-2026-53989: Dockhand before 1.0.36 contains an open redirect vulnerability in the OIDC initiation endpoint that
Dockhand before 1.0.36 contains an open redirect vulnerability in the OIDC initiation endpoint that allows unauthenticated remote attackers to redirect authenticated users to attacker-controlled sites by injecting an unvalidated redirect query parameter. Attackers can craft a malicious link targeting the OIDC callback flow to capture authorization co
nvd