OAuth Token Handling Flaw in Docker Sandboxes Affects Security
CVE-2026-105570

6.7MEDIUM

Key Information:

Vendor

Docker

Vendor
CVE Published:
8 October 2026

What is CVE-2026-105570?

A vulnerability exists in Docker Sandboxes related to the handling of OAuth token-endpoint hostnames, which are compared in a case-sensitive manner. This inconsistency with DNS hostname routing—treated case-insensitively—can allow untrusted code running within a sandbox to exploit a case-variant hostname. By doing so, it could access genuine provider endpoints and bypass masking of response tokens. If the OAuth flow is completed, this flaw could lead to the exposure of sensitive access and refresh tokens within the sandbox, compromising user credentials.

Affected Version(s)

Docker Sandboxes Linux 0.21.0 < 0.47.0

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.