Description
Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers could forward unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens or a derived Anthropic API key intended to remain outside the sandbox.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to Docker Sandboxes 0.47.0 or later.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 08 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers could forward unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens or a derived Anthropic API key intended to remain outside the sandbox. | |
| Title | Fail-open response masking in Docker Sandboxes can expose proxy-managed credentials | |
| First Time appeared |
Docker
Docker docker Sandboxes |
|
| Weaknesses | CWE-636 | |
| CPEs | cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Docker
Docker docker Sandboxes |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-10-08T19:27:49.633Z
Reserved: 2026-09-28T16:32:15.536Z
Link: CVE-2026-101998
No data.
Status : Received
Published: 2026-10-08T19:16:56.400
Modified: 2026-10-08T19:16:56.400
Link: CVE-2026-101998
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-636
Not Failing Securely ('Failing Open')