Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3v9w-6365-9w54 | Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy) |
Fri, 29 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amirraminfar
Amirraminfar dozzle |
|
| CPEs | cpe:2.3:a:amirraminfar:dozzle:*:*:*:*:*:docker:*:* | |
| Vendors & Products |
Amirraminfar
Amirraminfar dozzle |
Wed, 27 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amir20
Amir20 dozzle |
|
| Vendors & Products |
Amir20
Amir20 dozzle |
Tue, 26 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that sends an HTTP POST to the supplied URL with attacker-controlled request headers, and returns the response status code AND up to 1MB of the response body to the caller, when the target replies non-2xx. This vulnerability is fixed in 10.5.2. | |
| Title | Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy) | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-27T14:23:39.845Z
Reserved: 2026-05-11T20:14:43.201Z
Link: CVE-2026-45298
Updated: 2026-05-27T14:23:29.607Z
Status : Analyzed
Published: 2026-05-26T22:16:43.733
Modified: 2026-06-17T10:51:53.200
Link: CVE-2026-45298
No data.
OpenCVE Enrichment
Updated: 2026-06-18T13:00:16Z
Github GHSA