By vendor
Dokku vulnerabilities
Known CVEs affecting Dokku products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-45407MEDIUM 5.0
Dokku, a containerized platform-as-a-service tool, inadvertently exposes git credentials to local users when setting up authentication. The vulnerability exists in versions before 0.38.2, where a shell command used to initialize credential storage files doesn't set secure file permissions, leaving git authentication tokens readable by anyone with local system access. This is a local privilege escalation and credential theft risk specific to multi-user Dokku deployments.