Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to Docker Sandboxes 0.47.0 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Docker sandboxes
|
|
| Vendors & Products |
Docker sandboxes
|
Thu, 08 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could use a case-variant hostname to reach the genuine provider endpoint while bypassing response masking. If a user completed the OAuth flow, the provider's access and refresh tokens could be returned unmasked to the sandbox, exposing host-managed credentials. | |
| Title | Docker Sandboxes OAuth response masking could be bypassed with a case-variant token host | |
| First Time appeared |
Docker
Docker docker Sandboxes |
|
| Weaknesses | CWE-178 | |
| CPEs | cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Docker
Docker docker Sandboxes |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-10-08T19:28:28.605Z
Reserved: 2026-10-05T16:05:53.033Z
Link: CVE-2026-105570
Updated: 2026-10-08T19:28:13.076Z
Status : Awaiting Analysis
Published: 2026-10-08T19:16:57.133
Modified: 2026-10-08T20:46:35.260
Link: CVE-2026-105570
No data.
OpenCVE Enrichment
Updated: 2026-10-08T21:00:11Z
-
CWE-178
Improper Handling of Case Sensitivity