GPU VulnDB

Database/Container, Kubernetes & orchestration

Dozzle: restricted users receive container stats and lifecycle events outside their label scope

CVSS 4.3CVE-2026-62286Container, Kubernetes & orchestrationcurated

Impact

Dozzle applies a restricted user's label filter to container listings but not to the container-stat and container-event channels of GET /api/events/stream. Any authenticated restricted account in a simple-auth deployment therefore sees names, images, full label maps, CPU and memory use, network and disk totals, and deploy/restart activity for every container on every monitored host. Where Dozzle is used to give a team or a tenant a scoped view of a shared GPU host, that scoping does not hold for telemetry: one tenant learns what other tenants are running and how hard they are running it. Log contents, environment values and exec access are not exposed.

Who can reach it

An authenticated Dozzle user with a restricted per-user label filter, reaching the web UI over the network. No privilege escalation and no host access required - the normal account is enough.

What to do

Update the Dozzle image to 10.6.7 or later and restart the container; it is a single stateless viewer process, so this is seconds of downtime for the UI and no impact on the monitored workloads. Until then, treat per-user label filters as a convenience rather than a tenancy boundary and restrict Dozzle access to operators.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.