Back to database
Soon59Medium5.9VulnerabilityCVE-2026-105452No patch link observed

CVE-2026-105452 — Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy.

Published Oct 8, 2026, 07:16 PM UTCIngested 3h agoSource NVD(cve-db)CVE-2026-105452

Description

Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only when their values matched known sentinel values, so untrusted code in an authorized sandbox could supply an unrecognized credential in another supported authentication header. For affected upstream services, this could authenticate the request to an attacker-controlled account and expose data included in the request.

CVSS v4.0 base metrics

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.9

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Local

Attack Vector

AC

Low

Attack Complexity

AT

Present

Attack Requirements

PR

None

Privileges Required

UI

None

User Interaction

VC

High

Confidentiality (Vulnerable System)

VI

None

Integrity (Vulnerable System)

VA

None

Availability (Vulnerable System)

SC

None

Confidentiality (Subsequent System)

SI

None

Integrity (Subsequent System)

SA

None

Availability (Subsequent System)