๐Ÿ” CVE Alert

CVE-2026-105452

UNKNOWN 0.0

Docker Sandboxes egress proxy could forward unrecognized client credentials to managed hosts

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only when their values matched known sentinel values, so untrusted code in an authorized sandbox could supply an unrecognized credential in another supported authentication header. For affected upstream services, this could authenticate the request to an attacker-controlled account and expose data included in the request.

CWE CWE-200
Vendor docker
Product docker sandboxes
Ecosystems
Industries
Technology
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for docker docker sandboxes

Be the first to know when new unknown vulnerabilities affecting docker docker sandboxes are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Docker / Docker Sandboxes
0.21.0 < 0.43.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.docker.com: https://docs.docker.com/ai/sandboxes/ docs.docker.com: https://docs.docker.com/ai/sandboxes/configuration/credentials/#how-credential-injection-works

Credits

Hillel Twersky