VulnSea

tugtainer vulnerabilities

CVEs whose affected-version data names the tugtainer package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-87004High· 8.1PoC
today

Tugtainer is a self-hosted app for automating updates of Docker containers

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity p…

▾ MidnightQuenary · tugtainervia NVD
CVE-2026-55494Critical· 9.8PoC
today

Tugtainer is a self-hosted app for automating updates of Docker containers

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request sign…

▾ AbyssalQuenary · tugtainervia NVD
CVE-2026-55181Critical· 9.4
today

Tugtainer is a self-hosted app for automating updates of Docker containers

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports t…

▾ MidnightQuenary · tugtainervia NVD
CVE-2026-62308Critical· 9.1
today

Tugtainer is a self-hosted app for automating updates of Docker containers

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through th…

▾ MidnightQuenary · tugtainervia NVD
tugtainer vulnerabilities (CVEs) · VulnSea