11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/amir20/dozzle is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 4.3
CVE-2026-62286
Dozzle label filters do not restrict container event and statistics streams
UNKNOWN
CVE-2026-73087
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
UNKNOWN
CVE-2026-73087
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle
CRITICAL 9.6
CVE-2026-44985
Dozzle's Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpointsbypasses authentication
UNKNOWN
CVE-2026-44985
Dozzle's Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpointsbypasses authentication in github.com/amir20/dozzle
HIGH 8.6
CVE-2026-45298
Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)
UNKNOWN
CVE-2026-45298
Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy) in github.com/amir20/dozzle
UNKNOWN
CVE-2026-24740
Dozzle Agent Label-Based Access Control Bypass Allows Unauthorized Container Shell Access in github.com/amir20/dozzle
UNKNOWN
CVE-2026-24740
Dozzle Agent Label-Based Access Control Bypass Allows Unauthorized Container Shell Access
MEDIUM 4.8
CVE-2024-47182
Dozzle uses unsafe hash for passwords
UNKNOWN
CVE-2024-47182
Dozzle uses unsafe hash for passwords in github.com/amir20/dozzle
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes