Path Traversal Vulnerability in Dozzle Log Download Feature
CVE-2026-102332
4.6MEDIUM
What is CVE-2026-102332?
In Dozzle versions prior to 11.1.2, a security flaw exists in the log download endpoint related to inadequate sanitization of container display names. This vulnerability allows attackers who can assign labels to containers to exploit path traversal sequences, potentially enabling them to write files outside of the intended extraction directory during the download process. This can lead to unauthorized access to sensitive files or malicious file injection when users extract their logs.
Affected Version(s)
dozzle 8.9.1 < 11.1.2
