PT-2026-70785 · Dozzle · Dozzle
CVE-2026-73087
·
Published
2026-08-11
·
Updated
2026-09-10
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Dozzle versions 10.5.2 through 10.6.14
Description
The
isBlockedIP SSRF guard in internal/notification/dispatcher/webhook.go, utilized by safeDialContext for webhook notification URLs, fails to inspect IPv4 addresses embedded within 6to4, NAT64, Teredo, or IPv4-compatible IPv6 addresses. This allows an authenticated user to bypass the guard and reach loopback or link-local targets. SSRF (Server-Side Request Forgery) is a flaw where an attacker can induce the server to make requests to an unintended location.Recommendations
Update to version 10.6.15.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dozzle