CVE-2026-45407: Dokku Git Credentials Exposed via Insecure .netrc Permissions
Dokku, a containerized platform-as-a-service tool, inadvertently exposes git credentials to local users when setting up authentication. The vulnerability exists in versions before 0.38.2, where a shell command used to initialize credential storage files doesn't set secure file permissions, leaving git authentication tokens readable by anyone with local system access. This is a local privilege escalation and credential theft risk specific to multi-user Dokku deployments.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.0 MEDIUM · CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-522
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-26 / 2026-06-26
NVD description (verbatim)
Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch command, which applies the default umask of 0644. This pre-creation defeats the netrc binary's built-in 0600 permission setting, leaving git credentials readable by any local user who can traverse the dokku home directory. This vulnerability is fixed in 0.38.2.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
In Dokku versions prior to 0.38.2, the git:auth command uses bash's touch utility to pre-create the $DOKKU_ROOT/.netrc file before populating it with credentials. The touch command respects the system umask (typically 0644), which results in world-readable file permissions. Although the netrc binary is designed to enforce 0600 permissions (readable only by the owner), the pre-creation bypasses this protection mechanism. The resulting .netrc file remains readable by any local user able to traverse the dokku home directory, enabling credential disclosure. The fix ensures proper permissions are applied during file creation, preventing the umask bypass.
Business impact
Organizations deploying Dokku in multi-tenant or shared-host environments face credential exposure risk. Local users or compromised application containers can read plaintext git credentials, potentially enabling unauthorized code repository access, supply chain compromise, and lateral movement within development infrastructure. The impact is confined to local threat actors but is severe when Dokku runs on shared systems or in containerized environments with weak isolation boundaries.
Affected systems
Dokku versions prior to 0.38.2 are affected. The vulnerability applies specifically to deployments using the git:auth command to configure authentication. Systems where multiple local users share access to the Dokku home directory are at highest risk. Users running version 0.38.2 or later are not affected.
Exploitability
Exploitation requires local system access and the ability to navigate to the $DOKKU_ROOT directory. Once accessible, an attacker can read the unencrypted .netrc file and extract git credentials in plaintext. No special privileges, tools, or user interaction beyond file system traversal are required. The CVSS vector (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N) reflects that exploitation is low-complexity, requires low privilege, and carries high confidentiality impact with no integrity or availability compromise. The UI:R flag indicates some user interaction may factor into the scenario model.
Remediation
Upgrade to Dokku version 0.38.2 or later. The patch corrects the file creation process to ensure .netrc is created with 0600 permissions, preventing the umask bypass. Organizations unable to upgrade immediately should restrict local user access to the Dokku home directory via file system permissions or directory structure isolation. Credential rotation after patching is prudent given the exposure window.
Patch guidance
Apply the upgrade to Dokku 0.38.2 or any subsequent version. Verify the patch by confirming that newly created .netrc files have 0600 permissions (readable and writable only by the dokku user). Test the git:auth command in a non-production environment to ensure credentials are properly stored and git operations remain functional. Restart or redeploy affected applications after patching.
Detection guidance
Audit existing .netrc files in $DOKKU_ROOT to identify any with permissions greater than 0600 using 'ls -la' or 'stat' commands. Log git:auth command executions and monitor for any instances of file permission changes on .netrc. For forensic analysis, check access logs for unauthorized reads of the Dokku home directory by unprivileged users. Implement file integrity monitoring to detect unauthorized modifications to credential files.
Why prioritize this
This vulnerability merits prompt remediation in any multi-user or shared-host Dokku deployment. Although the CVSS score is moderate (5.0 MEDIUM), the local access requirement does not diminish the severity of exposing plaintext git credentials, which are high-value attack targets. Organizations should prioritize based on deployment model: shared-host or multi-tenant Dokku instances should receive urgent attention, while single-tenant or isolated deployments are lower-risk but still warrant timely patching.
Risk score, explained
The CVSS 3.1 score of 5.0 MEDIUM reflects a local attack vector (AV:L), low attack complexity (AC:L), and requirement for low privilege (PR:L). The high confidentiality impact (C:H) from credential exposure is offset by the local-only scope and lack of integrity or availability impact. The score does not capture the full context of supply chain risk or lateral movement potential from stolen git credentials; organizations should consider business context when evaluating priority.
Frequently asked questions
Does this vulnerability affect my Dokku instance if I don't use the git:auth command?
No. This vulnerability is specific to the git:auth command. If your Dokku setup does not rely on this command for authentication, you are not affected. However, if in doubt, verify your configuration and consider upgrading regardless to benefit from other security improvements.
Can I work around this without upgrading?
Partial mitigation is possible by restricting file system permissions on the Dokku home directory to prevent unprivileged users from accessing it. Use chmod to ensure the .netrc file and parent directories are readable only by the dokku user. However, this does not eliminate the underlying flaw and is not a substitute for patching. Upgrade as soon as possible.
Should I rotate my git credentials after upgrading?
Yes. Given the exposure window, it is prudent to assume git credentials may have been accessed. Rotate credentials in your git repositories after upgrading and deploying the patch. This limits the window of exposure for any credentials that may have been compromised.
How do I verify the patch was applied correctly?
After upgrading to 0.38.2, run 'ls -la' or 'stat' on the .netrc file in $DOKKU_ROOT to confirm permissions are 0600. If upgrading in place, test the git:auth command to ensure git operations continue to function normally. Perform integration testing in a staging environment if possible.
This analysis is based on the CVE description and CVSS vector provided as of the publication date. No exploit code has been disclosed, and this analysis does not constitute a guarantee of exploitability or risk. Security impact may vary based on deployment architecture, local access controls, and credential sensitivity. Organizations should verify patch availability and applicability against official Dokku release notes and advisories. This content is for informational and educational purposes and should inform, not replace, independent security assessment and vendor guidance. Source: NVD (public-domain), retrieved 2026-08-05. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2024-45636MEDIUMIBM QRadar EDR Plaintext Credential Storage (3.12–3.12.24)
- CVE-2025-7386MEDIUMHitachi Storage Navigator Information Exposure Vulnerability
- CVE-2026-11827MEDIUMGitLab EE Credential Access Vulnerability – Affected Versions & Patches
- CVE-2026-14019MEDIUMGoogle Chrome Password Manager Cross-Origin Data Leak Vulnerability
- CVE-2026-32315MEDIUMmotionEye Configuration File Permissions Exposure (Medium)
- CVE-2026-39908MEDIUMOpenBullet2 NTLMv2 Hash Disclosure via UNC Proxy Path
- CVE-2026-41715MEDIUMReactor Netty HTTP Redirect Credential Leakage Vulnerability
- CVE-2026-42951MEDIUMMacGregor VDR G4E Backup Credential Disclosure – Patch Guidance