CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-45298Public Exploit

Dozzle - SSRF (CVE-2026-45298)

PublishedMay 26, 2026
First SeenJun 25, 2026
Last Seen
Reported
CVSS8.6
web_application

Description

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default Dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that sends an HTTP POST to the supplied URL with attacker-controlled request headers, and returns the response status code AND up to 1MB of the response body to the caller, when the target replies non-2xx. This vulnerability is fixed in 10.5.2.

psychologyCrowdSec Analysis

CVE-2026-45298 is a server-side request forgery (SSRF) vulnerability in Dozzle, a real-time log viewer for Docker containers. In default deployments prior to version 10.5.2, unauthenticated attackers can exploit the /api/notifications/test-webhook endpoint to make arbitrary HTTP POST requests to attacker-specified URLs, potentially exposing sensitive internal resources and leaking up to 1MB of response data. This flaw could be leveraged for internal network scanning, data exfiltration, or probing internal services that are otherwise inaccessible.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

CrowdSec network observations suggest that most exploitation of CVE-2026-45298 involves focused reconnaissance to identify viable targets. Attackers typically tailor their campaigns based on system exposure and configuration. It is unlikely that a given attack is accidental. CrowdSec network telemetry also shows that exploitation of CVE-2026-45298 has significantly declined over the past week. Attack volumes are well below the long-term average, suggesting attackers are rapidly losing interest. The vulnerability appears to be falling out of active use across most threat landscapes.

Attackers exploit unauthenticated POST requests to /api/notifications/test-webhook, supplying attacker-controlled URLs in the JSON body to trigger server-side request forgery (SSRF) and access internal resources.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-05-26
Rule Released2026-06-24
CrowdSec First Seen2026-06-25

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.