Credential Exposure in Docker Sandbox Environments
CVE-2026-101998

5.9MEDIUM

Key Information:

Vendor

Docker

Vendor
CVE Published:
8 October 2026

What is CVE-2026-101998?

An issue has been identified in Docker Sandboxes where they may inadvertently expose sensitive credentials during error handling. Specifically, when an error occurs, the response body may return unmasked credential data alongside the error message. This flaw allows code running within an authorized sandbox environment to potentially access host-managed OAuth access and refresh tokens, as well as a derived Anthropic API key that should otherwise remain protected. This poses significant risks to data integrity and confidentiality in applications utilizing Docker Sandboxes for operational security.

Affected Version(s)

Docker Sandboxes Linux 0.21.0 < 0.47.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Irad Aharoni
.