Authenticated Server-Side Request Forgery in Tugtainer by Quenary
CVE-2026-62308
9.1CRITICAL
What is CVE-2026-62308?
Tugtainer, a self-hosted app designed for automating Docker container updates, prior to version 1.30.6, contains a vulnerability that allows authenticated users to exploit the /settings/test_notification endpoint. This endpoint directly processes arbitrary user-supplied URLs without restrictions on protocols, hostnames, or IP ranges, leading to potential malicious outbound HTTP requests. This behavior can be exploited as an authenticated blind SSRF, which could allow attackers to access sensitive internal services or perform actions on behalf of the server. An update has been made available with version 1.30.6, which addresses this issue.
Affected Version(s)
tugtainer < 1.30.6
