Description
Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could use a case-variant hostname to reach the genuine provider endpoint while bypassing response masking. If a user completed the OAuth flow, the provider's access and refresh tokens could be returned unmasked to the sandbox, exposing host-managed credentials.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to Docker Sandboxes 0.47.0 or later.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 08 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could use a case-variant hostname to reach the genuine provider endpoint while bypassing response masking. If a user completed the OAuth flow, the provider's access and refresh tokens could be returned unmasked to the sandbox, exposing host-managed credentials. | |
| Title | Docker Sandboxes OAuth response masking could be bypassed with a case-variant token host | |
| First Time appeared |
Docker
Docker docker Sandboxes |
|
| Weaknesses | CWE-178 | |
| CPEs | cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Docker
Docker docker Sandboxes |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-10-08T19:28:28.605Z
Reserved: 2026-10-05T16:05:53.033Z
Link: CVE-2026-105570
No data.
Status : Received
Published: 2026-10-08T19:16:57.133
Modified: 2026-10-08T19:16:57.133
Link: CVE-2026-105570
No data.
OpenCVE Enrichment
No data.
Weaknesses