CVE-2026-105452

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only when their values matched known sentinel values, so untrusted code in an authorized sandbox could supply an unrecognized credential in another supported authentication header. For affected upstream services, this could authenticate the request to an attacker-controlled account and expose data included in the request.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-10-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-10-08: 1Mentions · 2026-10-09: 110-0810-09
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew

    CVE-2026-105452 Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only w… https://www.cve.org/CVERecord?id=CVE-2026-105452

    00000845
    58.1K followersView on X
  • VulniPulse@vulnipulse

    CVE advisory: CVE-2026-105452 - docker: Docker Sandboxes egress proxy could forward unrecognized client credentials to managed hosts. https://vulnipulse.com/advisories/docker-cve-2026-105452 #CVE #CyberSecurity #Docker #DockerSandboxes

    0000028
    12 followersView on X

Explore more