Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105570— Docker Sandboxes OAuth response masking could be bypassed with a case-variant token host

Quick assessment

Affected
Docker Docker Sandboxes
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在判断是否对托管凭证响应进行屏蔽时,Docker Sandboxes 对 OAuth 令牌端点的 hostname 进行了区分大小写的比较,而请求路由则对 DNS hostname 进行了不区分大小写的处理。沙箱内的不受信代码可以利用大小写变体的 hostname 访问真实的提供商端点,从而绕过响应屏蔽机制。如果用户完成了 OAuth 流程,提供商的访问令牌和刷新令牌将以未屏蔽形式返回给沙箱,从而导致主机托管凭证泄露。

CVSS 6.7 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
Docker Docker Sandboxes 0.21.0< 0.47.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105570

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Docker Sandboxes OAuth response masking could be bypassed with a case-variant token host
Source: CVE Program / CVE List V5
Vulnerability Description
Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could use a case-variant hostname to reach the genuine provider endpoint while bypassing response masking. If a user completed the OAuth flow, the provider's access and refresh tokens could be returned unmasked to the sandbox, exposing host-managed credentials.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
大小写敏感处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Docker Docker Sandboxes 0.21.0 ~ 0.47.0 cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-105570

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105570

请登录查看更多情报信息。

Vendor Pages for CVE-2026-105570 (1)

Same Patch Batch · Docker · 2026-10-08 · 3 CVEs total

CVE-2026-105452 5.9 MEDIUM Docker Sandboxes egress proxy could forward unrecognized client credentials to managed hos
CVE-2026-101998 5.9 MEDIUM Fail-open response masking in Docker Sandboxes can expose proxy-managed credentials

IV. Related Vulnerabilities

V. Comments for CVE-2026-105570

No comments yet


Leave a comment