Threat Advisory

Dozzle Flaw Bypasses User Container Filters during Event Streaming

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-62286 is a vulnerability in github.com/amir20/dozzle with a CVSS score of 4.3 that allows unauthorized guest users to access sensitive information about secret containers through unfiltered container-stat and container-event streams. This flaw enables guests to obtain secret container IDs and attributes despite being restricted from accessing them via the documented filtered channel, potentially leading to data breaches and unauthorized access.

RECOMMENDATIONS:

  • We recommend you to update github.com/amir20/dozzle to below version:
  • https://github.com/advisories/GHSA-xcw9-qmmf-vqxj

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-62286 is a vulnerability in github.com/amir20/dozzle with a CVSS score of 4.3 that allows unauthorized guest users to access sensitive information about secret containers through unfiltered container-stat and container-event streams. This flaw enables guests to obtain secret container IDs and attributes despite being restricted from accessing them via the documented filtered channel, potentially leading to data breaches and unauthorized access.

RECOMMENDATIONS:

  • We recommend you to update github.com/amir20/dozzle to below version:
  • https://github.com/advisories/GHSA-xcw9-qmmf-vqxj

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu