Skip to main content
Vulnerability Database/CVE-2026-62286

CVE-2026-62286: Dozzle Information Disclosure Vulnerability

CVE-2026-62286 is an information disclosure flaw in Dozzle that allows restricted users to access container telemetry and lifecycle events beyond their authorized scope. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-62286 Overview

Dozzle is a realtime log viewer for Docker containers. Versions prior to 10.6.7 contain an information disclosure flaw in the streamEvents function within internal/web/events.go. The function applies a restricted user's label filter to container lists but omits that filter from the container-stat and container-event channels returned by GET /api/events/stream. In simple-auth deployments using per-user filters, any authenticated restricted account can receive telemetry and lifecycle events for containers outside its authorized label scope. This issue is tracked under [CWE-200] and is resolved in version 10.6.7.

Critical Impact

Authenticated restricted users can enumerate container names, images, full label maps, CPU and memory usage, network and disk totals, and lifecycle activity for containers across monitored hosts outside their authorized scope.

Affected Products

  • Dozzle versions prior to 10.6.7
  • Deployments configured with simple-auth and per-user label filters
  • Any monitored Docker host exposed through the Dozzle events stream endpoint

Discovery Timeline

  • 2026-09-24 - CVE CVE-2026-62286 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-62286

Vulnerability Analysis

The vulnerability resides in the server-sent events (SSE) handler exposed at GET /api/events/stream. Dozzle supports per-user label filters that constrain which containers a restricted account may observe. The streamEvents function in internal/web/events.go enforces this filter when returning container list payloads but does not apply the same scope check to the container-stat and container-event channels. As a result, telemetry and lifecycle events bypass the authorization boundary intended by the simple-auth configuration.

Exposed data includes container names, images, full label maps, CPU and memory utilization, network and disk totals, and start, stop, and restart activity across all monitored hosts. The handler does not expose log content, environment variable values, or exec access, which limits the data confidentiality impact to resource telemetry and container metadata.

Root Cause

The root cause is a missing authorization check in the event dispatcher. The code path that enforces label filtering for container list responses is not reused by the stat and event channels. This inconsistent enforcement of access control across sibling SSE channels represents an authorization gap classified under [CWE-200] Exposure of Sensitive Information to an Unauthorized Actor.

Attack Vector

An attacker needs valid credentials for a restricted Dozzle account. After authenticating, the attacker opens a connection to GET /api/events/stream and consumes the SSE channels. The container-stat and container-event events arrive for containers outside the account's authorized label scope, allowing passive enumeration of workloads and infrastructure topology without triggering any additional privileged action.

text
 event: containers-changed
 data: []
 
+/* snapshot: Test_handler_streamEvents_filtered */
+event: containers-changed
+data: [{"id":"visible","name":"visible","image":"test",...}]
+
+event: container-event
+data: {"name":"start","host":"localhost","actorId":"visible","time":"0001-01-01T00:00:00Z"}

Source: GitHub Commit 19c01e0. The patch adds a Test_handler_streamEvents_filtered snapshot that verifies only containers matching the restricted user's label filter appear in the stat and lifecycle channels.

Detection Methods for CVE-2026-62286

Indicators of Compromise

  • Long-lived SSE connections from restricted user accounts to /api/events/stream sustained across many containers
  • Access logs showing restricted accounts receiving stat or lifecycle events for hosts or label scopes they are not authorized to view
  • Dozzle instances running versions below 10.6.7 with simple-auth and per-user label filters configured

Detection Strategies

  • Audit Dozzle version strings reported by running containers and flag any instance below 10.6.7
  • Review the Dozzle configuration for users.yml entries that define per-user label filters, which indicates exposure to this flaw
  • Correlate authenticated requests to /api/events/stream against the container label scope assigned to each user account

Monitoring Recommendations

  • Forward Dozzle HTTP access logs to a centralized log store and alert on sustained connections to the events stream endpoint
  • Monitor Docker daemon activity for enumeration patterns that align with telemetry scraping from restricted accounts
  • Track installed Dozzle image digests in container registries to identify unpatched deployments

How to Mitigate CVE-2026-62286

Immediate Actions Required

  • Upgrade Dozzle to version 10.6.7 or later on all monitored hosts
  • Rotate credentials for any restricted accounts that could have observed out-of-scope telemetry
  • Review Docker container label schemas to confirm that labels used for authorization do not themselves leak sensitive metadata

Patch Information

The fix is published in Dozzle release v10.6.7 and tracked in GitHub Security Advisory GHSA-xcw9-qmmf-vqxj. The code change is documented in Pull Request 4803 and commit 19c01e0, which applies the per-user label filter to the stat and lifecycle event channels in streamEvents.

Workarounds

  • Disable restricted user accounts until the upgrade to 10.6.7 is complete
  • Restrict network access to the Dozzle web interface so that only trusted administrators can reach /api/events/stream
  • Deploy separate Dozzle instances per label scope rather than relying on per-user filters within a shared instance
bash
# Verify the running Dozzle version and upgrade the container
docker inspect --format '{{.Config.Image}}' dozzle
docker pull amir20/dozzle:v10.6.7
docker stop dozzle && docker rm dozzle
docker run -d --name dozzle -p 8080:8080 \
  -v /var/run/docker.sock:/var/run/docker.sock \
  amir20/dozzle:v10.6.7

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.