CVE-2026-45408Dokku · Dokku
Vulnerability data via NVD (ingested)
Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash pre-receive hook script via an unquoted heredoc (<<EOF instead of <<'EOF') in fn-git-create-hook() at plugins/git/internal-functions:378. On git push, bash interprets the semicolon as a command separator, executing arbitrary commands as the dokku user. This vulnerability is fixed in 0.38.2.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-45408product:"Dokku Dokku"http.html:"Dokku"More intel sources (5)
vuln:CVE-2026-45408vulnerabilities.cve_id: CVE-2026-45408CVE-2026-45408CVE-2026-45408"CVE-2026-45408" exploit -site:nvd.nist.gov