---
id: CVE-2026-105452
title: >-
  Docker Sandboxes could forward a client-supplied credential alongside a
  credential injected by the host egress proxy
summary: >-
  Docker Sandboxes could forward a client-supplied credential alongside a
  credential injected by the host egress proxy. The proxy removed alternate
  credentials only when their values matched known sentinel values, so untrusted
  code in an a…
severity: none
cwe:
  - CWE-200
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:46:35.260'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105452'
references:
  - url: 'https://docs.docker.com/ai/sandboxes/'
    label: security@docker.com
  - url: >-
      https://docs.docker.com/ai/sandboxes/configuration/credentials/#how-credential-injection-works
    label: security@docker.com
tags:
  - nvd
ingestedAt: '2026-10-08T20:06:22.180Z'
---

## Overview

Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only when their values matched known sentinel values, so untrusted code in an authorized sandbox could supply an unrecognized credential in another supported authentication header. For affected upstream services, this could authenticate the request to an attacker-controlled account and expose data included in the request.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
