quenary has 5 CVEs on record between 2025 and 2026. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 9.4 (critical), with 4 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.4
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-55494Critical· 9.8Tugtainer is a self-hosted app for automating updates of Docker containers66CVE-2026-55181Critical· 9.4Tugtainer is a self-hosted app for automating updates of Docker containers64CVE-2026-62308Critical· 9.1Tugtainer is a self-hosted app for automating updates of Docker containers62CVE-2026-87004High· 8.1Tugtainer is a self-hosted app for automating updates of Docker containers57CVE-2025-69201Critical· 9.8Tugtainer is a self-hosted app for automating updates of docker containers54
quenary vulnerabilities
CVEs affecting quenary, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-87004High· 8.1PoCTugtainer is a self-hosted app for automating updates of Docker containers
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity p…
CVE-2026-55494Critical· 9.8PoCTugtainer is a self-hosted app for automating updates of Docker containers
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request sign…
CVE-2026-55181Critical· 9.4PoCTugtainer is a self-hosted app for automating updates of Docker containers
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports t…
CVE-2026-62308Critical· 9.1PoCTugtainer is a self-hosted app for automating updates of Docker containers
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through th…
CVE-2025-69201Critical· 9.8Tugtainer is a self-hosted app for automating updates of docker containers
Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtainer-agent `POST api/command/run`. Version 1.15.1 fixes the issue.