CVE-2026-105570
Awaiting Analysis Awaiting Analysis - Queue

Docker Sandboxes OAuth Token Hostname Case Sensitivity Bypass

Vulnerability report for CVE-2026-105570, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Docker Inc.

Description

Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could use a case-variant hostname to reach the genuine provider endpoint while bypassing response masking. If a user completed the OAuth flow, the provider's access and refresh tokens could be returned unmasked to the sandbox, exposing host-managed credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Docker Docker Sandboxes 0.21.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-178 The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when masking credentials, but request routing treated them case-insensitively. This mismatch allowed untrusted code in a sandbox to bypass response masking by using a case-variant hostname to reach the genuine OAuth provider endpoint. If a user completed the OAuth flow, tokens could be returned unmasked to the sandbox, exposing host-managed credentials.

Detection Guidance

This vulnerability involves Docker Sandboxes incorrectly handling OAuth token-endpoint hostnames due to case sensitivity mismatches. Detection requires checking Docker Sandbox configurations and OAuth token handling. Review Docker logs for OAuth-related requests and verify if hostnames are processed case-sensitively. No specific commands are provided in the context.

Impact Analysis

An attacker in a Docker Sandbox could steal OAuth access and refresh tokens by exploiting this case-sensitivity flaw. This could lead to unauthorized access to user accounts, data breaches, or persistent control over affected systems if tokens grant long-term access.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Organizations may face compliance violations, fines, or reputational damage if tokens are exposed.

Mitigation Strategies

Update Docker Sandboxes to the latest version to ensure case-sensitive hostname matching is enforced consistently. Review OAuth token endpoint configurations to confirm hostnames are validated case-sensitively. Monitor for unusual credential exposure in sandboxed environments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105570. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart