CVE-2026-62308

Published: Set 30, 2026 Last Modified: Set 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,1
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: low
Availability: low

Description

AI Translation Available

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This can be abused as an authenticated blind server-side request forgery (SSRF). This issue has been patched in version 1.30.6.

918

Server-Side Request Forgery (SSRF)

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Integrity Access Control
Potential Impacts:
Read Application Data Execute Unauthorized Code Or Commands Bypass Protection Mechanism
Applicable Platforms
Technologies: Web Based, AI/ML, Web Server
View CWE Details
https://github.com/Quenary/tugtainer/commit/c0294d0ab64985b135d0c5b566ac30bf837…
https://github.com/Quenary/tugtainer/releases/tag/v1.30.6
https://github.com/Quenary/tugtainer/security/advisories/GHSA-c2h5-ppv9-7vrq