HighVulnerabilityLLM-specific
CVE-2026-101998: Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-101998
- Published
- Record updated
Summary
Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers forwarded unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens, or a derived Anthropic API key, that were meant to stay outside the sandbox.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- InfoAnthropic’s AI gave Philadelphia police a fake tip about an unsolved homicideSame vendor · The Verge (AI)
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- InfoAnthropic Launches Free AI Vulnerability Scanner for Open-Source ProjectsSame vendor · The Hacker News
- InfoAnthropic bans users from being 'cruel' to its AI systemsSame vendor · BBC Technology
- InfoThe Download: AI’s refusal problem and weight-loss drug side effectsSame vendor · MIT Technology Review