๐Ÿ” CVE Alert

CVE-2026-105570

UNKNOWN 0.0

Docker Sandboxes OAuth response masking could be bypassed with a case-variant token host

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could use a case-variant hostname to reach the genuine provider endpoint while bypassing response masking. If a user completed the OAuth flow, the provider's access and refresh tokens could be returned unmasked to the sandbox, exposing host-managed credentials.

CWE CWE-178
Vendor docker
Product docker sandboxes
Ecosystems
Industries
Technology
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for docker docker sandboxes

Be the first to know when new unknown vulnerabilities affecting docker docker sandboxes are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Docker / Docker Sandboxes
0.21.0 < 0.47.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.docker.com: https://docs.docker.com/ai/sandboxes/ docs.docker.com: https://docs.docker.com/ai/sandboxes/configuration/credentials/#how-credential-injection-works