LOW
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
Published Aug 11, 2026
2.3
LOWCVSS 4.0
EPSS 0.46%
Description
Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal/notification/dispatcher/webhook.go, used by safeDialContext for webhook notification URLs, does not inspect IPv4 addresses embedded in 6to4, NAT64, Teredo, or IPv4-compatible IPv6 addresses, allowing an authenticated user to reach loopback or link-local targets that the guard intends to block. This issue is fixed in version 10.6.15.
Affected products
-
- Version < 10.6.15StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/amir20/dozzle
Go
Introduced 0 Fixed 1.29.1-0.20260804193351-8cf7ccd5ee04
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/amir20/dozzle | 0 | 1.29.1-0.20260804193351-8cf7ccd5ee04 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://github.com/advisories/GHSA-p2w3-6x73-2f6x Advisory
- https://github.com/amir20/dozzle/commit/8cf7ccd5ee041ecaea92b49951793d4d2393761f x_refsource_MISC
- https://github.com/amir20/dozzle/pull/4887 x_refsource_MISC
- https://github.com/amir20/dozzle/releases/tag/v10.6.15 x_refsource_MISC
- https://github.com/amir20/dozzle/security/advisories/GHSA-p2w3-6x73-2f6x exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-73087
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-p2w3-6x73-2f6x | Advisory | |
| https://github.com/amir20/dozzle/commit/8cf7ccd5ee041ecaea92b49951793d4d2393761f | x_refsource_MISC | |
| https://github.com/amir20/dozzle/pull/4887 | x_refsource_MISC | |
| https://github.com/amir20/dozzle/releases/tag/v10.6.15 | x_refsource_MISC | |
| https://github.com/amir20/dozzle/security/advisories/GHSA-p2w3-6x73-2f6x | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-73087 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 11, 2026
Updated Aug 11, 2026
Reserved Aug 10, 2026
Link CVE-2026-73087
CISA Vulnrichment
GHSA-P2W3-6X73-2F6X Updated Aug 11, 2026