
CVE-2026-105452 Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only w… https://www.cve.org/CVERecord?id=CVE-2026-105452
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only when their values matched known sentinel values, so untrusted code in an authorized sandbox could supply an unrecognized credential in another supported authentication header. For affected upstream services, this could authenticate the request to an attacker-controlled account and expose data included in the request.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

CVE-2026-105452 Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only w… https://www.cve.org/CVERecord?id=CVE-2026-105452

CVE advisory: CVE-2026-105452 - docker: Docker Sandboxes egress proxy could forward unrecognized client credentials to managed hosts. https://vulnipulse.com/advisories/docker-cve-2026-105452 #CVE #CyberSecurity #Docker #DockerSandboxes