cbcvebase.

Quenary Tugtainer vulnerabilities

7 known vulnerabilities affecting quenary/tugtainer.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH1

Vulnerabilities

Page 1 of 1
CVE-2026-47752P2CRITICALCVSS 9.9fixed in 1.30.22026-07-23
CVE-2026-47752 [CRITICAL] CWE-1336 CVE-2026-47752: Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed `jinja2.Environment`, allowing any authenticated user to execute arbitr
nvd
CVE-2026-55181P2CRITICALCVSS 9.4fixed in 1.30.32026-09-30
CVE-2026-55181 [CRITICAL] CWE-284 CVE-2026-55181: Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts the OIDC login flow, returns HT
nvd
CVE-2026-55494P2CRITICALCVSS 9.8fixed in 1.30.42026-09-30
CVE-2026-55494 [CRITICAL] CWE-284 CVE-2026-55494: Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature verification function returns success
nvd
CVE-2026-23846P3CRITICALCVSS 9.1fixed in 1.16.12026-01-19
CVE-2026-23846 [CRITICAL] CWE-598 CVE-2026-23846: Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.1 Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmits passwords via URL query parameters instead of the HTTP request body. This causes passwords to be logged in server access logs and potentially exposed through browser history, Referer headers, and
nvd
CVE-2026-62308P3CRITICALCVSS 9.1fixed in 1.30.62026-09-30
CVE-2026-62308 [CRITICAL] CWE-918 CVE-2026-62308: Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it direct
nvd
CVE-2025-69201P3CRITICALCVSS 9.8fixed in 1.15.12025-12-29
CVE-2025-69201 [CRITICAL] CWE-77 CVE-2025-69201: Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.1 Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtainer-agent `POST api/command/run`. Version 1.15.1 fixes the issue.
nvd
CVE-2026-87004P3HIGHCVSS 8.1fixed in 1.31.32026-09-30
CVE-2026-87004 [HIGH] CWE-347 CVE-2026-87004: Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verifi
nvd
Quenary Tugtainer vulnerabilities | cvebase