Vulnerability GO-2026-6592
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
6 hours ago
October 01, 2026 at 08:23 PM UTC
Dozzle label filters do not restrict container event and statistics streams in github.com/amir20/dozzle
v1.0.1 - v1.29.0
v1.0.1 - v1.29.0
Summary
Dozzle label filters do not restrict container event and statistics streams in github.com/amir20/dozzle
Details
Dozzle label filters do not restrict container event and statistics streams in github.com/amir20/dozzle
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
7 days ago
Dozzle label filters do not restrict container event and statistics streams
v1.0.1 - v1.29.0 GHSA-xcw9-qmmf-vqxj
v1.0.1 - v1.29.0 GHSA-xcw9-qmmf-vqxj
Unknown
21 days ago
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle
v1.0.1 - v1.29.0 GO-2026-6440
v1.0.1 - v1.29.0 GO-2026-6440
Low Risk
23 days ago
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
v1.0.1 - v1.29.0 GHSA-p2w3-6x73-2f6x
v1.0.1 - v1.29.0 GHSA-p2w3-6x73-2f6x
Unknown
3 months ago
Dozzle's Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpointsbypasses authentication in github.com/amir20/dozzle
v1.0.1 - v1.29.0 GO-2026-5449
v1.0.1 - v1.29.0 GO-2026-5449
Unknown
3 months ago
Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy) in github.com/amir20/dozzle
v1.0.1 - v1.29.0 GO-2026-5101
v1.0.1 - v1.29.0 GO-2026-5101
Impacted packages
Timeline
Published
6 hours ago
October 01, 2026 at 08:23 PM UTC
Last Modified
6 hours ago
October 01, 2026 at 08:45 PM UTC