{"data":{"id":"2be7a2a1-ae98-4f43-b9b6-8c95a28df671","title":"CVE-2026-101998: Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read…","summary":"Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers forwarded unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens, or a derived Anthropic API key, that were meant to stay outside the sandbox.","solution":"N/A -- no mitigation discussed in source.","labels":["security","privacy"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101998","publishedAt":"2026-10-08T19:16:56.400Z","cveId":"CVE-2026-101998","cweIds":["CWE-636"],"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["jailbreak","data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["Docker Sandboxes","Anthropic API key"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00163,"epssCheckedAt":"2026-10-10T03:00:39.353Z","kevDateAdded":null,"advisoryAliases":["GHSA-cc8x-7cv4-34m9"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:42:34.031Z","patchAvailable":null,"disclosureDate":"2026-10-08T19:16:56.400Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null}}