CVE-2026-62308: Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpoint
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/testnotification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This can be abused as an authenticated blind server-side request forgery (SSRF). This issue has been patched in version 1.30.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tugtainerto a version that resolves this vulnerability.Fixed in 1.30.6
Event History
Frequently Asked Questions
Which deployments are affected?
Self-hosted Tugtainer deployments running a version earlier than 1.30.6 are affected. The issue is reachable through the /settings/test_notification endpoint.
What access does an attacker need?
An attacker needs an authenticated Tugtainer account. No user interaction is required, and the attacker can supply arbitrary notification URLs to cause backend outbound HTTP requests.
What internal targets could be reached?
The endpoint did not restrict protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. An authenticated user could therefore direct requests toward internal services or cloud metadata endpoints reachable from the Tugtainer server.
What should be done if the service cannot be upgraded immediately?
The provided data identifies version 1.30.6 as the patch release but does not specify a workaround. Until upgrading, treat access to the notification test endpoint as security-sensitive and limit authenticated access as much as possible.