---
id: CVE-2026-105570
title: >-
  Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when
  deciding whether to mask managed credential responses, while request routing
  treated DNS hostnames case-insensitively
summary: >-
  Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when
  deciding whether to mask managed credential responses, while request routing
  treated DNS hostnames case-insensitively. Untrusted code inside a sandbox
  could u…
severity: none
cwe:
  - CWE-178
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:46:35.260'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105570'
references:
  - url: 'https://docs.docker.com/ai/sandboxes/'
    label: security@docker.com
  - url: >-
      https://docs.docker.com/ai/sandboxes/configuration/credentials/#how-credential-injection-works
    label: security@docker.com
tags:
  - nvd
ingestedAt: '2026-10-08T20:06:22.181Z'
---

## Overview

Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could use a case-variant hostname to reach the genuine provider endpoint while bypassing response masking. If a user completed the OAuth flow, the provider's access and refresh tokens could be returned unmasked to the sandbox, exposing host-managed credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
