CVE-2026-105452: Docker Sandboxes egress proxy could forward unrecognized client credentials to managed hosts
Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only when their values matched known sentinel values, so untrusted code in an authorized sandbox could supply an unrecognized credential in another supported authentication header. For affected upstream services, this could authenticate the request to an attacker-controlled account and expose data included in the request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Docker Sandboxesto a version that resolves this vulnerability.Fixed in 0.43.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
The issue affects authorized sandboxes that run untrusted code and can make requests through the host egress proxy to affected upstream services. The untrusted code can supply an additional credential using another supported authentication header.
What does an attacker need to exploit it?
An attacker needs the ability to execute untrusted code in an authorized sandbox and control a client credential value in a supported authentication header. The supplied credential must be unrecognized by the proxy's sentinel-value filtering.
What is the likely impact of successful exploitation?
A request may be authenticated to an attacker-controlled account at an affected upstream service while also carrying data from the sandbox request. This can expose data included in that request to the attacker-controlled account.