Credential Injection Vulnerability in Docker Sandboxes by Docker
CVE-2026-105452
5.9MEDIUM
What is CVE-2026-105452?
A vulnerability in Docker Sandboxes allows for the potential injection of untrusted client-supplied credentials alongside those provided by the host's egress proxy. This occurs when the proxy only removes alternate credentials that match pre-defined sentinel values. Consequently, unauthorized code in a sanctioned sandbox could supply an unknown credential in an authentication header that is supported, enabling attackers to authenticate against an account they control and gain unauthorized access to sensitive data transmitted within the request.
Affected Version(s)
Docker Sandboxes Linux 0.21.0 < 0.43.0
