Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-62308— Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpoint

Quick assessment

Affected
Quenary tugtainer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Tugtainer 是一款用于自动化更新 Docker 容器的自托管应用程序。在版本 1.30.6 之前,Tugtainer 允许经过身份验证的用户通过通知测试端点( )使后端服务器向任意用户提供的 URL 发起出站 HTTP 请求。该端点接受一个 字段,并将其直接传递给 Apprise 库,而未对协议、主机名、本地回环地址(localhost)、私有 IP 范围或云元数据服务地址进行任何限制。此漏洞可被利用为经过身份验证的盲型服务器端请求伪造(SSRF)攻击。该问题已在版本 1.30.6 中修复。

CVSS 9.1 · Critical EPSS 0.35% · P26

Possible ATT&CK Techniques 1 AI

T1090 · Proxy

Affected Version Matrix 1

VendorProduct Version RangeStatus
Quenary tugtainer < 1.30.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-62308

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This can be abused as an authenticated blind server-side request forgery (SSRF). This issue has been patched in version 1.30.6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Quenary tugtainer < 1.30.6 -

II. Public POCs for CVE-2026-62308

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-62308

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-62308 (1)

Vendor Advisories for CVE-2026-62308 (1)

Vendor Pages for CVE-2026-62308 (1)

Same Patch Batch · Quenary · 2026-09-30 · 4 CVEs total

CVE-2026-55494 9.8 CRITICAL Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SEC
CVE-2026-55181 9.4 CRITICAL Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false
CVE-2026-87004 8.1 HIGH Tugtainer: OIDC id_token claims accepted without signature/audience/expiry verification

IV. Related Vulnerabilities

V. Comments for CVE-2026-62308

No comments yet


Leave a comment