CVE-2026-44985
📛 CVE Title
(no title)
Description
Dozzle's Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpointsbypasses authentication
Description (MITRE) cveawg.mitre.org
Pulled from cveawg.mitre.org/api/cve/CVE-2026-44985 on 2026-08-01. Shown when MITRE's text differs from the cvelistV5 mirror.
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepting upgrade requests from any origin. Combined with the JWT cookie using SameSite: Lax, this enables Cross-Site WebSocket Hijacking (CSWSH). An attacker hosting a page on a same-site origin (e.g., a sibling subdomain, or another service on localhost) can initiate a WebSocket connection to the exec endpoint that carries the victim's valid JWT cookie, gaining interactive shell access in any container the victim is authorized to access. This vulnerability is fixed in 10.5.2.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- high
- CVSS score
- 8.8 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H- Effective score
- 8.8 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-44985
- Linked Threat
- CVE-2026-44985 — CVE-2026-44985
NVD / KEV / EPSS data refreshed 2026-05-24 23:57 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-32017 - Assigner
- GitHub_M
- Published
- May 26, 2026, 9:58:55 PM
- Updated
- May 28, 2026, 2:15:19 PM
- EUVD base score (CVSS 4.0)
-
8.7 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.2000
- Vendors
- amir20
- Products
-
dozzle (< 10.5.2)
- Aliases
-
GHSA-j643-x8pv-8m67
ENISA description: Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepting upgrade requests from any origin. Combined with the JWT cookie using SameSite: Lax, this enables Cross-Site WebSocket Hijacking (CSWSH). An attacker hosting a page on a same-site origin (e.g., a sibling subdomain, or another service on localhost) can initiate a WebSocket connection to the exec endpoint that carries the victim's valid JWT cookie, gaining interactive shell access in any container the victim is authorized to access. This vulnerability is fixed in 10.5.2.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://github.com/amir20/dozzle/releases/tag/v10.5.2 tenable:github.com
- https://github.com/amir20/dozzle/security/advisories/GHSA-j643-x8pv-8m67 tenable:github.com
- https://www.first.org/epss/ tenable:www.first.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-44985 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-44985 tenable:www.cve.org
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:blog.gridinsoft.com
Microsoft has confirmed exploitation of two Microsoft Defender vulnerabilities fixed in the May 2026 security update cycle. CVE - 2026 -41091 is an elevation-of-privilege flaw in the Microsoft Malware Protection Engine, while CVE - 2026 -45498 is a denial-of-service flaw in the Microsoft Defender Antimalware Platform . The first bug matters more for incident response because a local authorized ...
2026-05-26 02:50 UTC -
web:blog.qualys.com
RedSun is a zero-day LPE in Microsoft Defender with no patch available. Learn how to detect and mitigate it instantly using Qualys VMDR and TruRisk™ Eliminate.
2026-05-26 02:50 UTC -
web:cyberpress.org
Mitigation Under Binding Operational Directive (BOD) 22-01, all federal civilian executive branch (FCEB) agencies are mandated to apply vendor-provided mitigations by June 3, 2026 , or discontinue use of the affected product if patches are unavailable. CISA's guidance explicitly extends to cloud-hosted environments leveraging Microsoft Defender.
2026-05-26 02:50 UTC -
web:cybersecurefox.com
Microsoft has confirmed active exploitation of two vulnerabilities in Microsoft Defender: CVE - 2026 -41091 (privilege escalation to SYSTEM, CVSS 7.8) and CVE - 2026 -45498 (denial of service, CVSS 4.0). The CISA agency has added both vulnerabilities to the Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian agencies to remediate them by June 3, 2026 . Fixes are already ...
2026-05-26 02:50 UTC -
web:msrc.microsoft.com
Security Updates Acknowledgements
2026-05-26 02:50 UTC -
web:thecyberexpress.com
Microsoft confirms active exploitation of CVE - 2026 -41091 and CVE - 2026 -45498 in Defender, with CVSS-rated risks, KEV listing, and urgent patches issued.
2026-05-26 02:50 UTC -
web:www.archynewsy.com
Microsoft has issued a critical security advisory regarding two vulnerabilities within Microsoft Defender that are currently being exploited in the wild.
2026-05-26 02:50 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's April 2026 Patch Tuesday with security updates for 167 flaws, including 2 zero-day vulnerabilities.
2026-05-26 02:50 UTC -
web:www.crowdstrike.com
Microsoft has released security updates for 130 vulnerabilities, including 30 critical, in its May 2026 Patch Tuesday rollout.
2026-05-26 02:50 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-05-26 02:50 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.