{"ok":true,"trend":{"id":513654,"platform":"mastodon","region":"global","key":"🚨 cve-2026-55181 — cvss 9.4 critical tugtainer is a self-hosted app for automating updates of docker containers. prior t","title":"🚨 CVE-2026-55181 — CVSS 9.4 CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. Prior t","url":"https://mastodon.social/@stemshop/117361326783975273","first_seen":"2026-09-30T18:21:47.463596Z","last_seen":"2026-09-30T18:21:47.463596Z","last_rank":12,"peak_rank":12,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.66078125,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A critical vulnerability, CVE-2026-55181 with a CVSS score of 9.4, has been disclosed in Tugtainer, a self-hosted application used to automate updates of Docker containers. Versions before 1.30.3 allow OIDC authentication to be initiated even when OIDC is disabled, potentially letting attackers bypass authentication. Administrators are urged to upgrade to version 1.30.3 or later.","why":"Self-hosted server admins are discussing the flaw because it exposes widely used Docker management tooling to authentication bypass.","tone":"neutral","entities":["Tugtainer","CVE-2026-55181","Docker"],"summarized_at":"2026-09-30T18:23:59.340463Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1820},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Critical vulnerability found in Docker update tool Tugtainer","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-30T18:21:47.463596Z","rank":12,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@stemshop/117361326783975273","author":"stemshop","title":null,"snippet":"🚨 CVE-2026-55181 — CVSS 9.4 CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that…","posted_at":"2026-09-30T18:08:49.494000Z","likes":0}],"elsewhere":[],"window":"7d"}}