Path Traversal Vulnerability in Dozzle Log Download Feature
CVE-2026-102332

4.6MEDIUM

Key Information:

Vendor

Amir20

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-102332?

In Dozzle versions prior to 11.1.2, a security flaw exists in the log download endpoint related to inadequate sanitization of container display names. This vulnerability allows attackers who can assign labels to containers to exploit path traversal sequences, potentially enabling them to write files outside of the intended extraction directory during the download process. This can lead to unauthorized access to sensitive files or malicious file injection when users extract their logs.

Affected Version(s)

dozzle 8.9.1 < 11.1.2

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lazizbek Djurayev (Haad TC)
.