Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label containers can use path traversal sequences to write files outside the extraction directory when users download and extract logs.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label containers can use path traversal sequences to write files outside the extraction directory when users download and extract logs. | |
| Title | Dozzle before 11.1.2 Path Traversal via Log ZIP Download | |
| First Time appeared |
Amirraminfar
Amirraminfar dozzle |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:amirraminfar:dozzle:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Amirraminfar
Amirraminfar dozzle |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T22:21:39.746Z
Reserved: 2026-09-28T22:08:48.561Z
Link: CVE-2026-102332
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses