CVE-2026-102332
4.6
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N
Summary
Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label containers can use path traversal sequences to write files outside the extraction directory when users download and extract logs.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| amir20 | dozzle | 8.9.1 < 11.1.2 | affected |
Weaknesses
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
References
- https://github.com/amir20/dozzle/pull/5242
- https://github.com/amir20/dozzle/commit/bc07db73dd84ce2cb939b744e983a8cfdf29c644
- https://github.com/amir20/dozzle/releases/tag/v11.1.2
- https://github.com/amir20/dozzle/blob/v11.1.1/internal/web/download.go#L141-L146
- https://github.com/amir20/dozzle/blob/v11.1.1/internal/container/docker/client.go#L610-L614
- https://github.com/amir20/dozzle
- https://www.vulncheck.com/advisories/dozzle-before-11.1.2-path-traversal-via-log-zip-download
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.