# CVE-2026-45298: Dozzle - SSRF

> Live exploitation tracking for CVE-2026-45298 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-45298

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 8.6
- **Public exploit available:** Yes
- **Affected products:** Amir20 Dozzle
- **Weaknesses:** CWE-918 (Server-Side Request Forgery (SSRF))
- **Tags:** web_application

## Description

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default Dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that sends an HTTP POST to the supplied URL with attacker-controlled request headers, and returns the response status code AND up to 1MB of the response body to the caller, when the target replies non-2xx. This vulnerability is fixed in 10.5.2.

## CrowdSec analysis

[CVE-2026-45298](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-45298) is a server-side request forgery (SSRF) vulnerability in Dozzle, a real-time log viewer for Docker containers. In default deployments prior to version 10.5.2, unauthenticated attackers can exploit the /api/notifications/test-webhook endpoint to make arbitrary HTTP POST requests to attacker-specified URLs, potentially exposing sensitive internal resources and leaking up to 1MB of response data. This flaw could be leveraged for internal network scanning, data exfiltration, or probing internal services that are otherwise inaccessible.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

CrowdSec network observations suggest that most exploitation of CVE-2026-45298 involves focused reconnaissance to identify viable targets. Attackers typically tailor their campaigns based on system exposure and configuration. It is unlikely that a given attack is accidental.
CrowdSec network telemetry also shows that exploitation of CVE-2026-45298 has significantly declined over the past week. Attack volumes are well below the long-term average, suggesting attackers are rapidly losing interest. The vulnerability appears to be falling out of active use across most threat landscapes.

Attackers exploit unauthenticated POST requests to `/api/notifications/test-webhook`, supplying attacker-controlled URLs in the JSON body to trigger server-side request forgery (SSRF) and access internal resources.

## Timeline

- 2026-05-26: CVE Published. CVE-2026-45298 is published to NVD.
- 2026-06-24: Rule Released. CrowdSec releases a rule to detect CVE-2026-45298 exploitation attempts against the CrowdSec Network.
- 2026-06-25: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-45298 for the first time.

## References

- https://github.com/amir20/dozzle/releases/tag/v10.5.2
- https://github.com/amir20/dozzle/security/advisories/GHSA-3v9w-6365-9w54
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-45298.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-45298) follows observed exploitation activity for CVE-2026-45298. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
