CVE-2026-45298Amirraminfar · Dozzle
Vulnerability data via NVD (ingested)
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that sends an HTTP POST to the supplied URL with attacker-controlled request headers, and returns the response status code AND up to 1MB of the response body to the caller, when the target replies non-2xx. This vulnerability is fixed in 10.5.2.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-45298product:"Amirraminfar Dozzle"http.html:"Dozzle"More intel sources (5)
vuln:CVE-2026-45298vulnerabilities.cve_id: CVE-2026-45298CVE-2026-45298CVE-2026-45298"CVE-2026-45298" exploit -site:nvd.nist.gov