CVE-2026-102332 Overview
CVE-2026-102332 is a path traversal vulnerability [CWE-22] in Dozzle, a lightweight web-based log viewer for Docker containers. Versions before 11.1.2 fail to sanitize container display names when constructing ZIP archive entry names in the log download endpoint. An attacker who can label or name containers can embed path traversal sequences such as ../ in the container name. When a user downloads and extracts the resulting log archive, files can be written outside the intended extraction directory. The flaw was fixed in Dozzle v11.1.2 via commit bc07db7, which introduces a sanitizeFileName helper for ZIP entry names.
Critical Impact
Attackers with the ability to name containers can write arbitrary files to a victim's filesystem when the victim extracts a downloaded log archive, enabling potential integrity loss on the host that performs extraction.
Affected Products
- Dozzle versions prior to 11.1.2
- Dozzle log download endpoint (internal/web/download.go)
- Docker container environments monitored by vulnerable Dozzle instances
Discovery Timeline
- 2026-09-28 - CVE-2026-102332 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-102332
Vulnerability Analysis
Dozzle exposes an HTTP endpoint that packages container logs into a ZIP archive for download. When building the archive, Dozzle uses the container's display name as part of each ZIP entry name. The code path in internal/web/download.go at lines 141-146 in v11.1.1 does not validate or sanitize characters in that name before writing it into the archive header.
Because Docker allows operators to assign arbitrary labels and names to containers, an attacker who controls container naming can inject path traversal sequences into ZIP entry names. Standard ZIP extractors will honor these relative paths, writing archive contents outside the extraction directory chosen by the user. The impact is scoped to the host performing the extraction rather than the Dozzle server itself, which is consistent with the CVSS integrity-only impact on a subsequent system.
Root Cause
The root cause is missing input sanitization on container names used as ZIP archive entry names. The original code applied basic sanitization only to the optional name query parameter used for the outer ZIP filename, but not to the per-container entry names sourced from Docker metadata via internal/container/docker/client.go at lines 610-614.
Attack Vector
Exploitation requires two conditions: an attacker able to create or rename a container with a malicious name containing traversal sequences, and a legitimate Dozzle user who downloads the container logs and extracts the resulting archive with a permissive extraction tool. The attack is network-reachable through the Dozzle web UI and requires user interaction to trigger the write primitive on the victim host.
// Patch: internal/web/download.go - fix(download): sanitize container names
// used as zip entry names (#5242)
// Determine zip filename from optional name param or default
zipName := "container-logs"
- if name := r.URL.Query().Get("name"); name != "" {
- // Sanitize: keep only alphanumeric, hyphens, underscores, dots
- sanitized := strings.Map(func(r rune) rune {
- if (r >= 'a' && r <= 'z') || (r >= 'A' && r <= 'Z') || (r >= '0' && r <= '9') || r == '-' || r == '_' || r == '.' {
- return r
- }
- return '-'
- }, name)
- if sanitized != "" {
- zipName = sanitized
- }
+ if name := sanitizeFileName(r.URL.Query().Get("name")); name != "" {
+ zipName = name
}
// Set headers for zip file
Source: GitHub Commit bc07db7
Detection Methods for CVE-2026-102332
Indicators of Compromise
- Docker container names or labels containing ../, ..\, or absolute path characters visible in Dozzle inventory or docker ps output.
- ZIP archives downloaded from Dozzle whose entry names contain relative path segments when listed with unzip -l.
- Unexpected files appearing outside the extraction directory after a user extracts a Dozzle log archive.
Detection Strategies
- Inspect running containers for suspicious names using docker inspect and flag any name containing path separators or traversal sequences.
- Review Dozzle access logs for requests to the log download endpoint that returned archives generated from containers with abnormal names.
- Validate downloaded archives before extraction by enumerating entry names and rejecting archives with entries whose resolved path escapes the target directory.
Monitoring Recommendations
- Monitor Docker daemon events for container create and container rename operations that introduce non-standard characters in names.
- Alert on file writes to sensitive paths on workstations that routinely handle Dozzle log downloads.
- Track Dozzle version strings across the fleet and flag any instance running a version earlier than 11.1.2.
How to Mitigate CVE-2026-102332
Immediate Actions Required
- Upgrade all Dozzle deployments to v11.1.2 or later, which introduces the sanitizeFileName helper for ZIP entry names.
- Audit existing containers and remove or rename any with names containing ../, backslashes, or other path separators.
- Restrict Docker socket and container creation privileges to trusted operators to limit who can influence container names.
Patch Information
The fix is delivered in Dozzle Release v11.1.2 and implemented in Pull Request #5242. Additional advisory context is available in the VulnCheck Path Traversal Advisory.
Workarounds
- Avoid downloading log archives from Dozzle instances that monitor containers created by untrusted users until the upgrade is applied.
- Extract any required archives inside an isolated sandbox or container where writes outside the target directory cause no harm.
- Use extraction utilities that refuse entries with absolute paths or .. traversal, and validate archive contents before extraction.
# Verify installed Dozzle version and upgrade the container
docker inspect dozzle --format '{{.Config.Image}}'
docker pull amir20/dozzle:v11.1.2
docker stop dozzle && docker rm dozzle
docker run -d --name dozzle \
-v /var/run/docker.sock:/var/run/docker.sock \
-p 8080:8080 amir20/dozzle:v11.1.2
# Audit container names for path traversal sequences before download
docker ps --format '{{.Names}}' | grep -E '\.\.|/|\\' && \
echo 'Suspicious container name detected'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.