← Vulnerability feed

Vulnerability record · CVE-2026-45406 · published 26 June 2026

CVE-2026-45406: Dokku vulnerability

Dokku · Dokku

Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and then interpolates their filenames, unescaped, into a single-quoted shell string that is later parsed by eval. A filename containing a single quote breaks the quoting and allows command substitution to execute arbitrary commands on the host as the dokku user during the app's next deploy. This vulnerability is fixed in 0.38.2.

8.8 CVSS 3.1 High EPSS 0.53% · top 57.5% CWE-95 · CWE-95
8.8CVSS 3.1 base score
0.53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
26 Jun 2026Last modified by NVD

Description

Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and then interpolates their filenames, unescaped, into a single-quoted shell string that is later parsed by eval. A filename containing a single quote breaks the quoting and allows command substitution to execute arbitrary commands on the host as the dokku user during the app's next deploy. This vulnerability is fixed in 0.38.2.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-45406 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-54636Dokku os command injection vulnerabilityDokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku us…EPSS 0.53%9.0CVE-2026-45408Dokku os command injection vulnerabilityDokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authentic…EPSS 0.42%8.8CVE-2026-45405Dokku link following vulnerabilityDokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary di…EPSS 0.46%5.5CVE-2026-45407Dokku insufficiently protected credentials vulnerabilityDokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch command, which applies the defaul…EPSS 0.13%9.3CVE-2026-33017Langflow build_public_tmp endpoint unauthenticated remote code executionLangflow versions prior to 1.9.0 expose the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint without authentication, and when the optional data …KEVEPSS 25%analysed9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.8CVE-2024-36401GeoServer OGC request parameter XPath eval injection enables unauthenticated RCEGeoServer versions before 2.22.6, 2.23.6, 2.24.4, and 2.25.2 unsafely evaluate OGC request parameters as XPath expressions via the GeoTools commons-j…KEVEPSS 100%analysed7.8CVE-2023-7101Spreadsheet::ParseExcel Perl module code injection via Excel number format stringsSpreadsheet::ParseExcel 0.65, a Perl module for parsing Excel files, passes unvalidated input from a file into a string-type eval. Specifically, Numb…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2026-45406), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.