Retour à la veille

CVE-2026-101998

Publié : 8 octobre 2026
Modifié : 8 octobre 2026
Lien officiel NVD

Description détaillée

Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers could forward unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens or a derived Anthropic API key intended to remain outside the sandbox.

Références et Patchs