CVE-2026-102332 Details
Description
Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label containers can use path traversal sequences to write files outside the extraction directory when users download and extract logs.
A path traversal vulnerability has been identified in Dozzle versions prior to 11.1.2. The issue arises because the application fails to properly sanitize container display names when creating ZIP archive entries for the log download feature. This allows attackers who can label containers to manipulate the file paths, potentially writing files outside the intended extraction directory. The vulnerability is particularly concerning for users who download and extract logs, as it could lead to unauthorized file access or modification.
Users can update to Dozzle version 11.1.2 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/amir20/dozzle | [email protected] | ProductSource CodeVendor |
| https://github.com/amir20/dozzle/blob/v11.1.1/internal/container/docker/client.go#L610-L614 | [email protected] | Source CodeVendor |
| https://github.com/amir20/dozzle/blob/v11.1.1/internal/web/download.go#L141-L146 | [email protected] | Source CodeVendor |
| https://github.com/amir20/dozzle/commit/bc07db73dd84ce2cb939b744e983a8cfdf29c644 | [email protected] | Source CodeVendor |
| https://github.com/amir20/dozzle/pull/5242 | [email protected] | Issue TrackingSource CodeVendor |
| https://github.com/amir20/dozzle/releases/tag/v11.1.2 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/dozzle-before-11.1.2-path-traversal-via-log-zip-download | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| amir20 Dozzle | >= 8.9.1, < 11.1.2 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion