dozzle vulnerabilities
CVEs whose affected-version data names the dozzle package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-102332Medium· 6.1Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint
Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label containers can use path traversal sequences to write files outside the ext…
▾ Sunlitamir20 · dozzlevia NVD
CVE-2026-62286Medium· 4.3PoCDozzle is a realtime log viewer for docker containers
Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a restricted user's label filter to container lists but not to the container-stat and container-event channels returne…
▾ Twilightamir20 · dozzleEPSS 0.34%via NVD