tugtainer vulnerabilities
CVEs whose affected-version data names the tugtainer package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-87004High· 8.1PoCTugtainer is a self-hosted app for automating updates of Docker containers
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity p…
CVE-2026-55494Critical· 9.8PoCTugtainer is a self-hosted app for automating updates of Docker containers
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request sign…
CVE-2026-55181Critical· 9.4Tugtainer is a self-hosted app for automating updates of Docker containers
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports t…
CVE-2026-62308Critical· 9.1Tugtainer is a self-hosted app for automating updates of Docker containers
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through th…