Tugtainer 是一款用于自动化更新 Docker 容器的自托管应用程序。在版本 1.30.6 之前,Tugtainer 允许经过身份验证的用户通过通知测试端点( )使后端服务器向任意用户提供的 URL 发起出站 HTTP 请求。该端点接受一个 字段,并将其直接传递给 Apprise 库,而未对协议、主机名、本地回环地址(localhost)、私有 IP 范围或云元数据服务地址进行任何限制。此漏洞可被利用为经过身份验证的盲型服务器端请求伪造(SSRF)攻击。该问题已在版本 1.30.6 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55494 | 9.8 CRITICAL | Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SEC |
| CVE-2026-55181 | 9.4 CRITICAL | Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false |
| CVE-2026-87004 | 8.1 HIGH | Tugtainer: OIDC id_token claims accepted without signature/audience/expiry verification |
No comments yet