All 5 CVE vulnerabilities found in dozzle, with AI-generated Chinese analysis, references, and POCs.
Vendor: amir20
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-73087 | Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher CWE-918 | 2.3 | Low | 2026-08-11 |
| CVE-2026-45298 | Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy) CWE-918 | 8.6 | High | 2026-05-26 |
| CVE-2026-44985 | Dozzle: Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpoints bypasses authentication CWE-346 | - | - | 2026-05-26 |
| CVE-2026-24740 | Dozzle Agent Label-Based Access Control Bypass Allows Unauthorized Container Shell Access CWE-284 | 8.1AI | High AI | 2026-01-27 |
| CVE-2024-47182 | Dozzle uses unsafe hash for passwords CWE-328 | 4.8 | Medium | 2024-09-27 |
All 5 known CVE vulnerabilities affecting dozzle with full Chinese analysis, references, and POCs where available.