---
id: CVE-2026-62308
title: Tugtainer is a self-hosted app for automating updates of Docker containers
summary: >-
  Tugtainer is a self-hosted app for automating updates of Docker containers.
  Prior to version 1.30.6, Tugtainer allows an authenticated user to make the
  backend server send outbound HTTP requests to arbitrary user-supplied URLs
  through th…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L'
cwe:
  - CWE-918
vendor: Quenary
product: tugtainer
affected:
  - tugtainer < 1.30.6
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T20:17:34.140'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-62308'
references:
  - url: >-
      https://github.com/Quenary/tugtainer/commit/c0294d0ab64985b135d0c5b566ac30bf8371f9c3
    label: security-advisories@github.com
  - url: 'https://github.com/Quenary/tugtainer/releases/tag/v1.30.6'
    label: security-advisories@github.com
  - url: >-
      https://github.com/Quenary/tugtainer/security/advisories/GHSA-c2h5-ppv9-7vrq
    label: security-advisories@github.com
  - url: >-
      https://github.com/Quenary/tugtainer/security/advisories/GHSA-c2h5-ppv9-7vrq
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-30T19:26:48.772147Z'
ingestedAt: '2026-09-30T17:13:20.831Z'
---

## Overview

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This can be abused as an authenticated blind server-side request forgery (SSRF). This issue has been patched in version 1.30.6.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
