CVE-2026-62308
Received Received - Intake

Authenticated SSRF in Tugtainer via Notification Test Endpoint

Vulnerability report for CVE-2026-62308, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This can be abused as an authenticated blind server-side request forgery (SSRF). This issue has been patched in version 1.30.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
quenary tugtainer to 1.30.6 (exc)
quenary tugtainer 1.30.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-62308 is a Server-Side Request Forgery (SSRF) vulnerability in Tugtainer, a self-hosted Docker container update automation tool. The flaw exists in the /settings/test_notification endpoint, which allows authenticated users to send outbound HTTP requests to arbitrary URLs by passing a urls parameter. The application uses the Apprise library to process these URLs without proper validation, enabling attackers to bypass restrictions on protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata endpoints.

Detection Guidance

To detect this vulnerability, check if your Tugtainer instance is running a version prior to 1.30.6. Use commands like 'docker ps' to list containers and 'docker inspect <container_name> --format={{.Config.Image}}' to verify the version. Inspect network traffic logs for outbound HTTP requests from the Tugtainer container to unexpected destinations.

Impact Analysis

An attacker could exploit this to probe internal network services, interact with localhost-only services from the backend container or host, send requests to internal HTTP endpoints, or target cloud metadata services. The vulnerability is classified as blind SSRF since the response body is not directly returned to the attacker. This could lead to unauthorized access to sensitive internal systems or data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR (data protection) and HIPAA (health information privacy). Unauthorized network probing or access to internal systems could result in data breaches, triggering regulatory penalties and legal consequences.

Mitigation Strategies

Immediately upgrade Tugtainer to version 1.30.6 or later. If upgrading is not possible, restrict notification URLs by configuring NOTIFICATION_ALLOW_SCHEMES, NOTIFICATION_ALLOW_NETWORKS, and NOTIFICATION_ALLOW_ENDPOINTS in .env. Block outbound requests to localhost, private IPs, and cloud metadata endpoints at the network firewall level.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62308. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart