PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73087 amir20 CVE debrief

CVE-2026-73087 is a low-severity vulnerability in Dozzle, a real-time log viewer for Docker containers. The issue, fixed in version 10.6.15, allows an authenticated user to bypass the isBlockedIP SSRF guard and reach loopback or link-local targets that the guard intends to block. This vulnerability exists in versions 10.5.2 through 10.6.14 and could allow potential bypass of SSRF protections. Defenders should assess exposure and prioritize upgrading to version 10.6.15 if necessary. The CVE record and NVD entry provide details on the vulnerability.

Vendor
amir20
Product
dozzle
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-09-09
Advisory published
2026-08-11
Advisory updated
2026-09-09

Who should care

Defenders responsible for Dozzle installations, particularly those with authenticated user access, should assess exposure and prioritize upgrading to version 10.6.15 if necessary. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify exposure and plan for remediation. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Why it matters

CVE-2026-73087 is a low-severity vulnerability in Dozzle that allows authenticated users to bypass SSRF protections. Defenders should prioritize verifying exposure and upgrading to version 10.6.15 if necessary.

  • Potential bypass of SSRF protections by authenticated users
  • Possible access to loopback or link-local targets
  • Need for verification of Dozzle installations and user access
  • Priority on upgrading to version 10.6.15

Technical summary

The isBlockedIP SSRF guard in Dozzle's internal/notification/dispatcher/webhook.go does not inspect IPv4 addresses embedded in 6to4, NAT64, Teredo, or IPv4-compatible IPv6 addresses. This allows an authenticated user to reach loopback or link-local targets that the guard intends to block. The issue exists in versions 10.5.2 through 10.6.14 and is fixed in version 10.6.15. The vulnerability could allow potential bypass of SSRF protections by authenticated users, possibly accessing loopback or link-local targets. Defenders should prioritize verifying exposure of Dozzle installations to authenticated users and upgrading to version 10.6.15 if necessary.

Defensive priority

Defenders should prioritize verifying exposure of Dozzle installations to authenticated users and upgrading to version 10.6.15 if necessary.

Recommended defensive actions

  • Verify Dozzle installations for exposure to authenticated users
  • Upgrade to version 10.6.15 if necessary
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its existence in versions 10.5.2 through 10.6.14 and its fix in version 10.6.15. However, additional information on potential exploitation or impact is limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73087 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73087

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73087 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73087

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.