CRITICAL9.6CVE-2026-44985Dozzle's Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpointsbypasses authentication in github.com/amir20/dozzle from 0, <= 10.5.1
CRITICAL9.6CVE-2026-44985Dozzle's Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpointsbypasses authentication in github.com/amir20/dozzle from 0
HIGH8.6CVE-2026-45298Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy) in github.com/amir20/dozzle from 0, <= 8.14.12
HIGH8.6Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy) in github.com/amir20/dozzle
from 0
MEDIUM4.8Dozzle uses unsafe hash for passwords in github.com/amir20/dozzle
from 0, < 8.5.3
MEDIUM4.8Dozzle uses unsafe hash for passwords in github.com/amir20/dozzle
from 0
—Dozzle Agent Label-Based Access Control Bypass Allows Unauthorized Container Shell Access in github.com/amir20/dozzle
from 0, < 1.29.1-0.20260125230338-620e59aa2463
—Dozzle Agent Label-Based Access Control Bypass Allows Unauthorized Container Shell Access in github.com/amir20/dozzle
from 0, < 1.29.1-0.20260125230338-620e59aa2463