Description
Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers could forward unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens or a derived Anthropic API key intended to remain outside the sandbox.
Published: 2026-10-08
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Credentials exposed (host OAuth, refresh tokens, API key)
Action: Patch
AI Analysis

Impact

Docker Sandboxes can improperly reveal credential data when a response-body read returns data in the presence of an error. The affected handlers may forward unmasked bytes, allowing code running in an authorized sandbox to capture host‑managed OAuth access and refresh tokens or a derived API key that was intended to remain outside the sandbox. The result is the disclosure of privileged credentials that can be used to authenticate against host resources and external services, potentially enabling further compromise or unauthorized access.

Affected Systems

All Docker Sandboxes installations prior to 0.47.0 are affected. The vulnerability exists in the Docker Sandboxes platform and manifests when sandboxed code interacts with proxy responses that contain credential information.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate impact. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Since the flaw is accessed from within an authorized sandbox, the attack vector requires the ability to execute code inside the sandbox or supply crafted sandboxed input. An attacker who succeeds can obtain host‑level OAuth tokens or API keys, which can be leveraged for unauthorized API access or to move laterally into the host environment. The likelihood of exploitation is limited to scenarios where a sandboxed deployment is used with proxy‑managed credentials, but once the vulnerability is known it poses a significant risk to credential confidentiality.

Generated by OpenCVE AI on October 8, 2026 at 20:26 UTC.

Remediation

Vendor Solution

Upgrade to Docker Sandboxes 0.47.0 or later.


OpenCVE Recommended Actions

  • Upgrade Docker Sandboxes to version 0.47.0 or later
  • Review sandboxed code to eliminate paths that trigger response-body reads on error, or ensure sandbox policy blocks access to unmasked credential bytes
  • If an upgrade is not yet possible, disable proxy‑managed credential injection for sandboxes or reconfigure sandbox policies to restrict token exposure

Generated by OpenCVE AI on October 8, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers could forward unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens or a derived Anthropic API key intended to remain outside the sandbox.
Title Fail-open response masking in Docker Sandboxes can expose proxy-managed credentials
First Time appeared Docker
Docker docker Sandboxes
Weaknesses CWE-636
CPEs cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:*
Vendors & Products Docker
Docker docker Sandboxes
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Docker Docker Sandboxes
cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2026-10-08T19:27:49.633Z

Reserved: 2026-09-28T16:32:15.536Z

Link: CVE-2026-101998

cve-icon Vulnrichment

Updated: 2026-10-08T19:27:45.798Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:16:56.400

Modified: 2026-10-08T20:46:35.260

Link: CVE-2026-101998

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:30:18Z

Weaknesses
  • CWE-636

    Not Failing Securely ('Failing Open')