PatchSiren

amir20 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM amir20 CVE published 2026-09-24

CVE-2026-62286

CVE-2026-62286 debrief: Dozzle's streamEvents in internal/web/events.go applies a restricted user's label filter to container lists but not to the container-stat and container-event channels returned by GET /api/events/stream. This allows any authenticated restricted account to receive resource telemetry and lifecycle events for containers outside its authorized label scope.

LOW amir20 CVE published 2026-08-11

CVE-2026-73087

CVE-2026-73087 is a low-severity vulnerability in Dozzle, a real-time log viewer for Docker containers. The issue, fixed in version 10.6.15, allows an authenticated user to bypass the isBlockedIP SSRF guard and reach loopback or link-local targets that the guard intends to block. This vulnerability exists in versions 10.5.2 through 10.6.14 and could allow potential bypass of SSRF protections. Defenders sh [truncated]

HIGH amir20 CVE published 2026-05-26

CVE-2026-44985

A critical Cross-Site WebSocket Hijacking (CSWSH) vulnerability in Dozzle, a real-time Docker log viewer, enables attackers to gain interactive shell access to containers by exploiting a permissive WebSocket origin check combined with lax cookie security. The vulnerability affects versions prior to 10.5.2 and was disclosed on 2026-05-26.