Credential Injection Vulnerability in Docker Sandboxes by Docker
CVE-2026-105452

5.9MEDIUM

Key Information:

Vendor

Docker

Vendor
CVE Published:
8 October 2026

What is CVE-2026-105452?

A vulnerability in Docker Sandboxes allows for the potential injection of untrusted client-supplied credentials alongside those provided by the host's egress proxy. This occurs when the proxy only removes alternate credentials that match pre-defined sentinel values. Consequently, unauthorized code in a sanctioned sandbox could supply an unknown credential in an authentication header that is supported, enabling attackers to authenticate against an account they control and gain unauthorized access to sensitive data transmitted within the request.

Affected Version(s)

Docker Sandboxes Linux 0.21.0 < 0.43.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hillel Twersky
.