
If you run Dokku (self-hosted PaaS), upgrade to 0.38.2 today. CVE-2026-45406 is a command injection via filenames. Here's what breaks and how to fix it.
Post summary
Dokku 0.38.2 includes a patch that fixes CVE-2026-45406, a command‑injection vulnerability triggered by filenames; users should update immediately.

