Description
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This can be abused as an authenticated blind server-side request forgery (SSRF). This issue has been patched in version 1.30.6.
Published: 2026-09-30
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an authenticated user to trigger outbound HTTP requests to any URL via the /settings/test_notification endpoint. By supplying a crafted URL, the attacker can have the server contact internal or external services, exposing internal networks or obtaining sensitive data. The weakness arises from an unsanitized URLs field that is passed directly to Apprise without restricting protocol, hostname, or address ranges, and is categorized as CWE‑918.

Affected Systems

Quenary's Tugtainer application prior to version 1.30.6 is affected. Authenticated users running the self‑hosted container automation tool may be able to abuse the test_notification endpoint if they have not upgraded to the patched v1.30.6 release. The issue applies to all installations of the affected version on any supported platform.

Risk and Exploitability

The CVSS score of 9.1 signals a high‑severity vulnerability. Although EPSS data is unavailable and the issue is not listed in CISA KEV, the required authentication is typically available to legitimate users of the service, meaning any compromised account can perform blind SSRF attacks. The attacker can use the endpoint to scan internal networks, access metadata services, or exfiltrate data through outbound requests, thereby compromising confidentiality and potentially integrity of internal resources.

Generated by OpenCVE AI on September 30, 2026 at 20:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Tugtainer to version 1.30.6 or later, which removes the unsanitized URL handling in the test_notification endpoint.
  • If immediate upgrade is not feasible, restrict the /settings/test_notification API to a narrow set of authenticated, highly privileged users or disable it entirely to prevent abuse.
  • Configure network or host firewall rules to block or log unexpected outbound HTTP requests originating from the Tugtainer service to mitigate potential SSRF abuse while remediation is pending.

Generated by OpenCVE AI on September 30, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This can be abused as an authenticated blind server-side request forgery (SSRF). This issue has been patched in version 1.30.6.
Title Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpoint
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T19:27:22.748Z

Reserved: 2026-07-13T19:27:58.314Z

Link: CVE-2026-62308

cve-icon Vulnrichment

Updated: 2026-09-30T19:27:12.827Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T17:16:49.423

Modified: 2026-09-30T20:17:34.140

Link: CVE-2026-62308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T20:30:18Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)