Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade to Docker Sandboxes 0.43.0 or later.
Workaround
No workaround given by the vendor.
Thu, 08 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only when their values matched known sentinel values, so untrusted code in an authorized sandbox could supply an unrecognized credential in another supported authentication header. For affected upstream services, this could authenticate the request to an attacker-controlled account and expose data included in the request. | |
| Title | Docker Sandboxes egress proxy could forward unrecognized client credentials to managed hosts | |
| First Time appeared |
Docker
Docker docker Sandboxes |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Docker
Docker docker Sandboxes |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-10-08T19:29:41.004Z
Reserved: 2026-10-05T13:55:16.620Z
Link: CVE-2026-105452
Updated: 2026-10-08T19:29:36.812Z
Status : Awaiting Analysis
Published: 2026-10-08T19:16:56.717
Modified: 2026-10-08T20:46:35.260
Link: CVE-2026-105452
No data.
OpenCVE Enrichment
Updated: 2026-10-08T20:30:18Z