The number and severity of CVEs published that impact products developed by Dokku over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54636CRITICAL Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command ut | Jun 26, 2026 | 9.9 | 42 | NO | NO |
CVE-2026-45408CRITICAL Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remot | Jun 26, 2026 | 9.0 | 39 | NO | NO |
CVE-2026-45405HIGH Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanitizing me | Jun 26, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-45406HIGH Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and then inter | Jun 26, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-45407MEDIUM Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch command, which applies the default umask of 0644. This pre-creat | Jun 26, 2026 | 5.5 | 27 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dokku.
Media articles that mention a CVE ID that affects a product developed by Dokku — matched by CVE ID, not by vendor name.