PT-2026-70785 · Dozzle · Dozzle

CVE-2026-73087

·

Published

2026-08-11

·

Updated

2026-09-10

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Dozzle versions 10.5.2 through 10.6.14
Description The isBlockedIP SSRF guard in internal/notification/dispatcher/webhook.go, utilized by safeDialContext for webhook notification URLs, fails to inspect IPv4 addresses embedded within 6to4, NAT64, Teredo, or IPv4-compatible IPv6 addresses. This allows an authenticated user to bypass the guard and reach loopback or link-local targets. SSRF (Server-Side Request Forgery) is a flaw where an attacker can induce the server to make requests to an unintended location.
Recommendations Update to version 10.6.15.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73087
GHSA-P2W3-6X73-2F6X
GO-2026-6440

Affected Products

Dozzle