
CVE-2026-101998 Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected ha… https://www.cve.org/CVERecord?id=CVE-2026-101998
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers could forward unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens or a derived Anthropic API key intended to remain outside the sandbox.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

CVE-2026-101998 Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected ha… https://www.cve.org/CVERecord?id=CVE-2026-101998

CVE advisory: CVE-2026-101998 - docker: Fail-open response masking in Docker Sandboxes can expose proxy-managed credentials. https://vulnipulse.com/advisories/docker-cve-2026-101998 #CVE #CyberSecurity #Docker #DockerSandboxes