CVE-2026-72873
- EPSS 0.33%
- Veröffentlicht 10.08.2026 18:56:14
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/api/routers/application.ts returns provider relations loaded by findApplicationById in packages/server/src/services/application.ts...
CVE-2026-72872
- EPSS 0.37%
- Veröffentlicht 10.08.2026 18:50:23
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucketRepository in packages/server/src/utils/providers/bi...
CVE-2026-72871
- EPSS 0.29%
- Veröffentlicht 10.08.2026 18:47:58
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_init organizationId and userId values from the state ...
CVE-2026-72870
- EPSS 0.28%
- Veröffentlicht 10.08.2026 18:45:17
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in packages/server/src/utils/providers/docker.ts interpolates the application-controlled dockerImage value directly into a docker pull s...
CVE-2026-72869
- EPSS 0.35%
- Veröffentlicht 10.08.2026 18:40:48
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in packages/server/src/utils/restore/utils.ts, where PostgreSQL,...
CVE-2026-72868
- EPSS 0.36%
- Veröffentlicht 10.08.2026 18:39:08
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider, and bucket fields from destination.testConnection...
CVE-2026-72867
- EPSS 0.49%
- Veröffentlicht 10.08.2026 18:36:54
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without server-side validation, allowing a direct compose.up...
CVE-2026-72866
- EPSS 0.31%
- Veröffentlicht 10.08.2026 18:34:34
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/server/wss/terminal.ts validates a session but does not authorize access to the requested server. An authenticated user can connect...
CVE-2026-72865
- EPSS 0.35%
- Veröffentlicht 10.08.2026 18:33:05
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that packages/server/src/utils/builders/compose.ts and packages/server/src/services/compose.ts interpolate...
CVE-2026-72864
- EPSS 0.27%
- Veröffentlicht 10.08.2026 18:31:24
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates with validateRequest but does not authorize the atta...