PT-2026-102394 · Dozzle · Dozzle

·

CVE-2026-102332

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

6.1

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dozzle versions prior to 11.1.2
Description Insufficient sanitization of container display names occurs when building ZIP archive entry names in the log download endpoint. Attackers with the ability to label containers can employ path traversal sequences—a technique used to access files and directories outside the intended folder—to write files outside the extraction directory when users download and extract logs.
Recommendations Update to version 11.1.2 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102332

Affected Products

Dozzle