CVE-2026-101998EPSS p5.0%
CVE-2026-101998CVE-2026-101998
Description
Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers could forward unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens or a derived Anthropic API key intended to remain outside the sandbox.
Scoring
| EPSS | 0.16% probability of exploitation · percentile 5.0% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |