CVE-2026-87004High· 8.1▾ MidnightPoC availableTugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity p…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44.6 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
1 GitHub repo (last check)
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verification, audience (aud) validation, issuer (iss) validation, and expiry (exp) checking entirely. The extracted claims (email/sub/preferred_username) are then used directly as the user_id for the resulting Tugtainer session. This issue has been patched in version 1.31.3.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55181Critical· 9.4Tugtainer is a self-hosted app for automating updates of Docker containers
CVE-2026-55494Critical· 9.8Tugtainer is a self-hosted app for automating updates of Docker containers
CVE-2026-62308Critical· 9.1Tugtainer is a self-hosted app for automating updates of Docker containers
CVE-2026-1529High· 8.1A flaw was found in Keycloak
CVE-2026-55174Medium· 5.9UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes
CVE-2026-102275Medium· 6.5PyJWT is a Python implementation of JSON Web Token standards