Docker 沙箱可能会将客户端提供的凭据与主机出口代理注入的凭据一并转发。由于代理仅在备用凭据的值与已知哨兵值匹配时才移除它们,因此经过授权的沙箱中的不受信任代码可以在其他支持的身份验证头部中提供无法识别的凭据。对于受影响的上游服务,这可能导致请求被认证为攻击者控制的账户,并暴露请求中包含的数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Docker | Docker Sandboxes | 0.21.0< 0.43.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Docker | Docker Sandboxes | 0.21.0 ~ 0.43.0 |
cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105570 | 6.7 MEDIUM | Docker Sandboxes OAuth response masking could be bypassed with a case-variant token host |
| CVE-2026-101998 | 5.9 MEDIUM | Fail-open response masking in Docker Sandboxes can expose proxy-managed credentials |
No comments yet