๐Ÿ” CVE Alert

CVE-2026-73087

UNKNOWN 0.0

Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal/notification/dispatcher/webhook.go, used by safeDialContext for webhook notification URLs, does not inspect IPv4 addresses embedded in 6to4, NAT64, Teredo, or IPv4-compatible IPv6 addresses, allowing an authenticated user to reach loopback or link-local targets that the guard intends to block. This issue is fixed in version 10.6.15.

CWE CWE-918
Vendor amir20
Product dozzle
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for amir20 dozzle

Be the first to know when new unknown vulnerabilities affecting amir20 dozzle are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

amir20 / dozzle
< 10.6.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/amir20/dozzle/security/advisories/GHSA-p2w3-6x73-2f6x github.com: https://github.com/amir20/dozzle/pull/4887 github.com: https://github.com/amir20/dozzle/commit/8cf7ccd5ee041ecaea92b49951793d4d2393761f github.com: https://github.com/amir20/dozzle/releases/tag/v10.6.15