Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-62286— Dozzle label filters do not restrict container event and statistics streams

Quick assessment

Affected
amir20 dozzle
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Dozzle 是一个用于 Docker 容器的实时日志查看工具。在版本 10.6.7 之前, 中的 函数仅对容器列表应用了受限用户的标签过滤器,但未将该过滤器应用于通过 返回的容器统计和容器事件通道。在采用按用户过滤策略的简单认证部署环境中,任何经过身份验证的受限账户均可获取超出其授权标签范围之外的容器的资源遥测数据和生命周期事件。 暴露的数据包括容器名称、镜像、完整标签映射、CPU 和内存使用情况、网络与磁盘使用总量,以及被监控主机上的部署或重启活动;但不包括日志内容、环境变量或执行访问权限。该问题已在版本 10

CVSS 4.3 · Medium EPSS 0.34% · P25

Affected Version Matrix 1

VendorProduct Version RangeStatus
amir20 dozzle < 10.6.7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-62286

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Dozzle label filters do not restrict container event and statistics streams
Source: CVE Program / CVE List V5
Vulnerability Description
Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a restricted user's label filter to container lists but not to the container-stat and container-event channels returned by GET /api/events/stream. In a simple-auth deployment using per-user filters, any authenticated restricted account can receive resource telemetry and lifecycle events for containers outside its authorized label scope. The exposed data includes container names, images, full label maps, CPU and memory use, network and disk totals, and deployment or restart activity across monitored hosts, but does not include log contents, environment values, or exec access. This issue is fixed in version 10.6.7.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
amir20 dozzle < 10.6.7 -

II. Public POCs for CVE-2026-62286

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-62286

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-62286 (2)

Vendor Advisories for CVE-2026-62286 (1)

Vendor Pages for CVE-2026-62286 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-62286

No comments yet


Leave a comment