CVE-2026-62308 Details
Description
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This can be abused as an authenticated blind server-side request forgery (SSRF). This issue has been patched in version 1.30.6.
A blind server-side request forgery (SSRF) vulnerability has been identified in Tugtainer, a self-hosted application for automating Docker container updates. This vulnerability exists in versions prior to 1.30.6 and allows authenticated users to send outbound HTTP requests to arbitrary URLs specified by the user, through the '/settings/test_notification' endpoint. The vulnerability arises because the endpoint does not validate the URLs against restricted protocols, hostnames, or private IP ranges, enabling potential abuse of internal services or cloud metadata access.
Users can update to Tugtainer version 1.30.6 or later, where this vulnerability has been patched. For those unable to update, it is recommended to review and restrict notification URLs to prevent unauthorized outbound requests.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Quenary/tugtainer/security/advisories/GHSA-c2h5-ppv9-7vrq | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/Quenary/tugtainer/commit/c0294d0ab64985b135d0c5b566ac30bf8371f9c3 | [email protected] | Source CodeVendor |
| https://github.com/Quenary/tugtainer/releases/tag/v1.30.6 | [email protected] | Release NotesVendor |
| https://github.com/Quenary/tugtainer/security/advisories/GHSA-c2h5-ppv9-7vrq | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Quenary Tugtainer | <= 1.30.5 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion