WebSocket Vulnerability in Dozzle Log Viewer by Amir20
CVE-2026-44985

8.7HIGH

Key Information:

Vendor

Amir20

Status
Vendor
CVE Published:
26 May 2026

What is CVE-2026-44985?

Dozzle, a real-time log viewer for Docker containers, prior to version 10.5.2, has a vulnerability in its WebSocket upgrader that accepts connections from any origin. This flaw allows an attacker, hosting a page on the same-site origin, to exploit the vulnerable endpoints and hijack an active WebSocket connection using the victim's valid JWT cookie. Consequently, this grants the attacker interactive shell access to any container the victim has authorization to access. The issue is addressed in version 10.5.2.

Affected Version(s)

dozzle < 10.5.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.