WebSocket Vulnerability in Dozzle Log Viewer by Amir20
CVE-2026-44985
8.7HIGH
What is CVE-2026-44985?
Dozzle, a real-time log viewer for Docker containers, prior to version 10.5.2, has a vulnerability in its WebSocket upgrader that accepts connections from any origin. This flaw allows an attacker, hosting a page on the same-site origin, to exploit the vulnerable endpoints and hijack an active WebSocket connection using the victim's valid JWT cookie. Consequently, this grants the attacker interactive shell access to any container the victim has authorization to access. The issue is addressed in version 10.5.2.
Affected Version(s)
dozzle < 10.5.2
