CVE-2026-101998: Docker Sandboxes
Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.
Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers could forward unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens or a derived Anthropic API key intended to remain outside the sandbox.
Affected products
- Docker Docker Sandboxes: from 0.21.0, before 0.47.0 (fixed in 0.47.0)
Published 2026-10-08. Last modified 2026-10-08.