๐Ÿ” CVE Alert

CVE-2026-101998

UNKNOWN 0.0

Fail-open response masking in Docker Sandboxes can expose proxy-managed credentials

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers could forward unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens or a derived Anthropic API key intended to remain outside the sandbox.

CWE CWE-636
Vendor docker
Product docker sandboxes
Ecosystems
Industries
Technology
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for docker docker sandboxes

Be the first to know when new unknown vulnerabilities affecting docker docker sandboxes are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Docker / Docker Sandboxes
0.21.0 < 0.47.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.docker.com: https://docs.docker.com/ai/sandboxes/ docs.docker.com: https://docs.docker.com/ai/sandboxes/configuration/credentials/#how-credential-injection-works

Credits

๐Ÿ” Irad Aharoni