{"id":"CVE-2026-105570","title":"Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively","summary":"Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could u…","severity":"none","cwe":["CWE-178"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T20:46:35.260","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105570","references":[{"url":"https://docs.docker.com/ai/sandboxes/","label":"security@docker.com"},{"url":"https://docs.docker.com/ai/sandboxes/configuration/credentials/#how-credential-injection-works","label":"security@docker.com"}],"tags":["nvd"],"ingestedAt":"2026-10-08T20:06:22.181Z","slug":"CVE-2026-105570","body":"## Overview\n\nDocker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could use a case-variant hostname to reach the genuine provider endpoint while bypassing response masking. If a user completed the OAuth flow, the provider's access and refresh tokens could be returned unmasked to the sandbox, exposing host-managed credentials.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}