<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:53:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-321996</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-321996</link>
      <description>EUVD-2026-321996</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-321996</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45298</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45298</link>
      <description>&lt;p&gt;Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that sends an HTTP POST to the supplied URL with attacker-controlled request headers, and returns the response status code AND up to 1MB of the response body to the caller, when the target replies non-2xx. This vulnerability is fixed in 10.5.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that sends an HTTP POST to the supplied URL with attacker-controlled request headers, and returns the response status code AND up to 1MB of the response body to the caller, when the target replies non-2xx. This vulnerability is fixed in 10.5.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45298</guid>
    </item>
    <item>
      <title>GHSA-3v9w-6365-9w54 — Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3v9w-6365-9w54</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/amir20/dozzle&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In a default dozzle deploy (the documented quickstart, no `DOZZLE_AUTH_PROVIDER` set), `POST /api/notifications/test-webhook` is reachable without authentication and forwards an attacker-controlled URL into a `WebhookDispatcher` that:&lt;/p&gt;
&lt;p&gt;- Sends an HTTP POST to the supplied URL with attacker-controlled request headers, and
- Returns the response status code AND up to 1MB of the response body to the caller, when the target replies non-2xx.&lt;/p&gt;
&lt;p&gt;This is a classic full-reflection SSRF, pre-auth, against any IP/port that dozzle&amp;#39;s host can route to — including private subnets, link-local cloud metadata, and loopback services.&lt;/p&gt;
&lt;p&gt;## Affected versions&lt;/p&gt;
&lt;p&gt;`internal/notification/dispatcher/webhook.go` and `internal/web/notifications.go` at commit `581bab3a43ead84ea4d009a469a17af98fb3377f` and earlier (the test-webhook handler has been in place since the notifications subsystem was added).&lt;/p&gt;
&lt;p&gt;## Default-deploy reachability chain&lt;/p&gt;
&lt;p&gt;```
main.go:58-59           → enforces AuthProvider in {none, forward-proxy, simple}
support/cli/args.go:18  → AuthProvider default is &amp;#34;none&amp;#34;
main.go:231-243         → when AuthProvider == &amp;#34;none&amp;#34;, web.AuthProvider stays at NONE
internal/web/routes.go:130-132, 137-138 → auth middleware only registered if Provider != NONE
internal/web/routes.go:172-188          → /api/notifications/* (incl. /test-webhook) is inside that conditional Group
```&lt;/p&gt;
&lt;p&gt;So the default Quickstart deploy&lt;/p&gt;
&lt;p&gt;```bash
docker run -v /var/run/docker.sock:/var/run/docker.sock -p 8080:8080 amir20/do…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/amir20/dozzle&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In a default dozzle deploy (the documented quickstart, no `DOZZLE_AUTH_PROVIDER` set), `POST /api/notifications/test-webhook` is reachable without authentication and forwards an attacker-controlled URL into a `WebhookDispatcher` that:&lt;/p&gt;
&lt;p&gt;- Sends an HTTP POST to the supplied URL with attacker-controlled request headers, and
- Returns the response status code AND up to 1MB of the response body to the caller, when the target replies non-2xx.&lt;/p&gt;
&lt;p&gt;This is a classic full-reflection SSRF, pre-auth, against any IP/port that dozzle&amp;#39;s host can route to — including private subnets, link-local cloud metadata, and loopback services.&lt;/p&gt;
&lt;p&gt;## Affected versions&lt;/p&gt;
&lt;p&gt;`internal/notification/dispatcher/webhook.go` and `internal/web/notifications.go` at commit `581bab3a43ead84ea4d009a469a17af98fb3377f` and earlier (the test-webhook handler has been in place since the notifications subsystem was added).&lt;/p&gt;
&lt;p&gt;## Default-deploy reachability chain&lt;/p&gt;
&lt;p&gt;```
main.go:58-59           → enforces AuthProvider in {none, forward-proxy, simple}
support/cli/args.go:18  → AuthProvider default is &amp;#34;none&amp;#34;
main.go:231-243         → when AuthProvider == &amp;#34;none&amp;#34;, web.AuthProvider stays at NONE
internal/web/routes.go:130-132, 137-138 → auth middleware only registered if Provider != NONE
internal/web/routes.go:172-188          → /api/notifications/* (incl. /test-webhook) is inside that conditional Group
```&lt;/p&gt;
&lt;p&gt;So the default Quickstart deploy&lt;/p&gt;
&lt;p&gt;```bash
docker run -v /var/run/docker.sock:/var/run/docker.sock -p 8080:8080 amir20/do…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3v9w-6365-9w54</guid>
    </item>
  </channel>
</rss>
