CVE-2026-101998
Fail-open response masking in Docker Sandboxes can expose proxy-managed credentials
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers could forward unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens or a derived Anthropic API key intended to remain outside the sandbox.
| CWE | CWE-636 |
| Vendor | docker |
| Product | docker sandboxes |
| Ecosystems | |
| Industries | Technology |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for docker docker sandboxes
Be the first to know when new unknown vulnerabilities affecting docker docker sandboxes are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Docker / Docker Sandboxes
0.21.0 < 0.47.0
References
Credits
๐ Irad Aharoni