What is CVE-2026-72867?
CVE-2026-72867 affects the self-hostable Dokploy PaaS platform. Due to an incomplete fix for CVE-2026-45628, the branch fields in compose.ts lack server-side validation, allowing a direct compose.update request to inject a malicious customGitBranch. Affected users should apply updates and restrict input validation.
Azərbaycanca: CVE-2026-72867, özü host edilə bilən Dokploy PaaS platformasını təsir edir. Bu zəiflik, CVE-2026-45628 üçün natamam düzəliş nəticəsində compose.update sorğusu ilə server tərəfində yoxlanılmamış branch sahəsinə zərərli customGitBranch daxil etməyə imkan verir. Təsirə məruz qalan versiyaları işlədən istifadəçilər yeniləmə tətbiq etməli və daxilolma sorğularını məhdudlaşdırmalıdır.
FAQ2
What is the root cause of CVE-2026-72867?
The vulnerability arises from an incomplete fix for CVE-2026-45628, which results in the 'customGitBranch' parameter lacking server-side validation in a compose.update request.
What should Dokploy users do to protect against CVE-2026-72867?
Affected users should apply updates and restrict input validation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.