Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to Docker Sandboxes 0.43.0 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only when their values matched known sentinel values, so untrusted code in an authorized sandbox could supply an unrecognized credential in another supported authentication header. For affected upstream services, this could authenticate the request to an attacker-controlled account and expose data included in the request. | |
| Title | Docker Sandboxes egress proxy could forward unrecognized client credentials to managed hosts | |
| First Time appeared |
Docker
Docker docker Sandboxes |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Docker
Docker docker Sandboxes |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-10-08T19:29:41.004Z
Reserved: 2026-10-05T13:55:16.620Z
Link: CVE-2026-105452
No data.
Status : Received
Published: 2026-10-08T19:16:56.717
Modified: 2026-10-08T19:16:56.717
Link: CVE-2026-105452
No data.
OpenCVE Enrichment
No data.
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor