Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label containers can use path traversal sequences to write files outside the extraction directory when users download and extract logs. | |
| Title | Dozzle before 11.1.2 Path Traversal via Log ZIP Download | |
| First Time appeared |
Amirraminfar
Amirraminfar dozzle |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:amirraminfar:dozzle:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Amirraminfar
Amirraminfar dozzle |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T22:21:39.746Z
Reserved: 2026-09-28T22:08:48.561Z
Link: CVE-2026-102332
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')