CVE-2026-105570
Docker Sandboxes OAuth response masking could be bypassed with a case-variant token host
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could use a case-variant hostname to reach the genuine provider endpoint while bypassing response masking. If a user completed the OAuth flow, the provider's access and refresh tokens could be returned unmasked to the sandbox, exposing host-managed credentials.
| CWE | CWE-178 |
| Vendor | docker |
| Product | docker sandboxes |
| Ecosystems | |
| Industries | Technology |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for docker docker sandboxes
Be the first to know when new unknown vulnerabilities affecting docker docker sandboxes are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Docker / Docker Sandboxes
0.21.0 < 0.47.0