Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

4Qu4R1Um

#30447of 57,578
9.1Total CVSS
Vulnerabilities · 1
PT-2026-103471
9.1
2026-09-30
Tugtainer · Tugtainer · CVE-2026-62308
**Name of the Vulnerable Software and Affected Versions** Tugtainer versions prior to 1.30.6 **Description** An authenticated user can trigger the backend server to send outbound HTTP requests to arbitrary user-supplied URLs. This occurs via the '/settings/test notification' endpoint, which accepts a `urls` field and passes it to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This flaw enables an authenticated blind server-side request forgery (SSRF), a condition where an attacker induces the server to make requests to an unintended location. **Recommendations** Update to version 1.30.6.