Browse all 5 CVE security advisories affecting dokku. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-54636 | Dokku: OS Command Injection via app.json managed Cron — dokku CWE-78 | 9.0 | Critical | 2026-06-26 |
| CVE-2026-45405 | Dokku: Arbitrary File Write via Tar Symlink Traversal in git:from-archive and certs:add — dokku CWE-59 | 9.0 | Critical | 2026-06-26 |
| CVE-2026-45406 | Dokku: Host RCE via Maliciously Named OpenResty Include Files Injected Through eval — dokku CWE-95 | 9.0 | Critical | 2026-06-26 |
| CVE-2026-45407 | Dokku: Git Credentials in .netrc Stored World-Readable Due to Premature touch — dokku CWE-522 | 5.0 | Medium | 2026-06-26 |
| CVE-2026-45408 | Dokku: OS Command Injection via App Name in Git Pre-Receive Hook — dokku CWE-78 | 9.0 | Critical | 2026-06-26 |
This page lists every published CVE security advisory associated with dokku. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.