Docker · Docker Sandboxes · CVE-2026-101998
**Name of the Vulnerable Software and Affected Versions**
Docker Sandboxes (affected versions not specified)
**Description**
Docker Sandboxes may fail open when masking credentials in protected proxy responses. This occurs when a response-body read returns data simultaneously with an error, causing affected handlers to forward unmasked bytes. An authorized sandbox could exploit this behavior to recover host-managed OAuth access tokens, refresh tokens, or a derived Anthropic API key that should remain outside the sandbox environment.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.