Description
Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could use a case-variant hostname to reach the genuine provider endpoint while bypassing response masking. If a user completed the OAuth flow, the provider's access and refresh tokens could be returned unmasked to the sandbox, exposing host-managed credentials.
Published: 2026-10-08
Score: 6.7 Medium
EPSS: n/a
KEV: No
Impact: Credential compromise
Action: Immediate Patch
AI Analysis

Impact

The flaw lies in Docker Sandboxes’ handling of OAuth token-endpoint hostnames. The system compares hostnames case‑sensitively when deciding whether to mask the provider’s response, while DNS routing treats hostname comparisons case‑insensitively. This mismatch allows an attacker who can execute code within a sandbox to supply a case‑variant hostname that resolves to the real provider endpoint. When the OAuth flow is completed, the access and refresh tokens are returned unmasked to the sandbox and become exposed to the malicious code, effectively leaking the host‑managed credentials.

Affected Systems

The vulnerability affects Docker Sandboxes released prior to version 0.47.0. Any deployment using an unpatched Docker Sandboxes instance is susceptible, especially where untrusted code is allowed to run inside the sandbox environment.

Risk and Exploitability

The CVSS score of 6.7 indicates a moderate impact. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. An attacker would need to run code inside the sandbox – a capability typically granted to a loaded container image or script – and lease a case‑variant hostname to reach the provider. If achieved, the attacker can capture OAuth tokens and gain credential access, but the exploit requires presence of untrusted code within the environment and the ability to construct the credential injection scenario as described by the vendor documentation.

Generated by OpenCVE AI on October 8, 2026 at 20:27 UTC.

Remediation

Vendor Solution

Upgrade to Docker Sandboxes 0.47.0 or later.


OpenCVE Recommended Actions

  • Upgrade Docker Sandboxes to version 0.47.0 or later to correct the host‑name comparison logic
  • If an upgrade cannot be performed immediately, restrict sandbox execution by disabling custom credential injection or enforcing strict hostname validation in sandbox configuration
  • Ensure that OAuth tokens are not exposed to untrusted code by configuring the sandbox to isolate credential handling or using environment restrictions that prevent DNS-based hostname manipulation

Generated by OpenCVE AI on October 8, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could use a case-variant hostname to reach the genuine provider endpoint while bypassing response masking. If a user completed the OAuth flow, the provider's access and refresh tokens could be returned unmasked to the sandbox, exposing host-managed credentials.
Title Docker Sandboxes OAuth response masking could be bypassed with a case-variant token host
First Time appeared Docker
Docker docker Sandboxes
Weaknesses CWE-178
CPEs cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:*
Vendors & Products Docker
Docker docker Sandboxes
References
Metrics cvssV4_0

{'score': 6.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Docker Docker Sandboxes
cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2026-10-08T19:28:28.605Z

Reserved: 2026-10-05T16:05:53.033Z

Link: CVE-2026-105570

cve-icon Vulnrichment

Updated: 2026-10-08T19:28:13.076Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:16:57.133

Modified: 2026-10-08T20:46:35.260

Link: CVE-2026-105570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:30:18Z

Weaknesses
  • CWE-178

    Improper Handling of Case Sensitivity