VulnSea

Quenary has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 9.3 (critical), with 3 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.3
Publish → KEV
—
Last 90 days
4 prev 0

Products

  • tugtainer 4
4
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

Quenary vulnerabilities

CVEs affecting Quenary, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-87004High· 8.1PoC
today

Tugtainer is a self-hosted app for automating updates of Docker containers

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity p…

▾ MidnightQuenary · tugtainervia NVD
CVE-2026-55494Critical· 9.8PoC
today

Tugtainer is a self-hosted app for automating updates of Docker containers

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request sign…

▾ AbyssalQuenary · tugtainervia NVD
CVE-2026-55181Critical· 9.4
today

Tugtainer is a self-hosted app for automating updates of Docker containers

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports t…

▾ MidnightQuenary · tugtainervia NVD
CVE-2026-62308Critical· 9.1
today

Tugtainer is a self-hosted app for automating updates of Docker containers

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through th…

▾ MidnightQuenary · tugtainervia NVD
Quenary vulnerabilities (CVEs) · VulnSea