PULSE
FEED
ransombarracuda reclama a Ministarstvo poljoprivrede, šumarstva i ribarstva · HR · Agriculture and Food Productionransomsilentransomgroup reclama a O'Hagan Meyer · Professional Servicesransomnetrunner reclama a Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates · US · Healthcareransomumbra reclama a SOCOCO · FR · Technologyransomeclipse reclama a dipecarr.com.br · BR · Manufacturingransomqilin reclama a MCM Telecom · MX · Technologyransomsilentransomgroup reclama a Baker McKenzie · US · Professional Servicesransomumbra reclama a Manipal Academy of Higher Edu · IN · Educationransomumbra reclama a IIT Roorkee · IN · Educationransomumbra reclama a FSE, Cairo University · EG · Educationransompayload reclama a Boullard Musique · FR · Retail & E-Commerceransomeclipse reclama a simplexengg.in · IN · Manufacturingransomeclipse reclama a sanjoseattorneys.com · US · Professional Servicesransomsilentransomgroup reclama a Andersen Group Inc. · Professional Servicesransombarracuda reclama a Ministarstvo poljoprivrede, šumarstva i ribarstva · HR · Agriculture and Food Productionransomsilentransomgroup reclama a O'Hagan Meyer · Professional Servicesransomnetrunner reclama a Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates · US · Healthcareransomumbra reclama a SOCOCO · FR · Technologyransomeclipse reclama a dipecarr.com.br · BR · Manufacturingransomqilin reclama a MCM Telecom · MX · Technologyransomsilentransomgroup reclama a Baker McKenzie · US · Professional Servicesransomumbra reclama a Manipal Academy of Higher Edu · IN · Educationransomumbra reclama a IIT Roorkee · IN · Educationransomumbra reclama a FSE, Cairo University · EG · Educationransompayload reclama a Boullard Musique · FR · Retail & E-Commerceransomeclipse reclama a simplexengg.in · IN · Manufacturingransomeclipse reclama a sanjoseattorneys.com · US · Professional Servicesransomsilentransomgroup reclama a Andersen Group Inc. · Professional Services
← All CVEs
CVE WatchOct 8, 2026

CVE-2026-105452

Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alte

CVSS

—

No CVSS

EPSS

—

KEV

—

Exploit Today

0

0-100

Published: Oct 8, 2026 · Last modified: Oct 8, 2026 · CWE-200

EPSS · 30d

Not enough EPSS history yet.

Technical description

Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only when their values matched known sentinel values, so untrusted code in an authorized sandbox could supply an unrecognized credential in another supported authentication header. For affected upstream services, this could authenticate the request to an attacker-controlled account and expose data included in the request.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1077156.8 MED
—
——0The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize::HTTP::Agent#request_add_headers even after Mechanize::HTTP::Agent#response_redirect strips per-request headers, and the protected header lists omit Proxy-Authorization and Cookie2. An attacker who controls a redirect target can capture bearer tokens or session cookies supplied through request_headers= or the per-request headers argument, while Mechanize#cookie_jar and Mechanize::HTTP::AuthStore are not affected. This issue is fixed in version 2.14.1.11h
CVE-2026-1077145.9 MED
—
——0The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize::HTTP::Agent#response_redirect treats redirects as same-origin when the host matches without consistently comparing scheme and port. A same-host HTTPS-to-HTTP redirect can send Authorization and Cookie headers over cleartext, while a same-host redirect to another port can send a caller-supplied Cookie header to a different service. Cookies in Mechanize#cookie_jar remain scoped separately; the issue affects caller-supplied headers and can disclose credentials without affecting integrity or availability. This issue is fixed in version 2.14.1.11h
CVE-2026-1073996.8 MED
—
——0The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A page containing a meta refresh to another origin causes headers configured through Mechanize#request_headers= to be reapplied to the refresh request, allowing an attacker who controls content in the crawl to capture bearer tokens or session cookies. The default configuration is not affected because follow_meta_refresh is false, and the exposure is limited to caller-supplied default headers. This issue is fixed in version 2.14.1.11h
CVE-2026-842746.5 MED
—
——0IBM Guardium Data Protection 12.2.2 is affected by a sensitive information exposure vulnerability. During SECRET and API_KEY rotation processing, sensitive credential material is logged at INFO level by the edge-controller/edge-manager components. An authenticated attacker with access to the relevant application or container logs could obtain these credentials and use them to impersonate services or gain unauthorized access to the Guardium control plane.13h
CVE-2026-1073837.5 HIG
—
——0MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop skips, and the connector sends the full buffer through execute() or batch(), disclosing uninitialized Node.js heap data into a database value. The persisted data can include other users' content, session material, database credentials, or TLS key material and may propagate to backups and replicas. The text-protocol query() path is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.13h
CVE-2026-1076044.9 MED
—
——0A flaw was found in the installation provider and client registration endpoints of the Keycloak identity management service. A realm administrator with only the read-only view-clients role can access the active primary secret of any confidential client, which should normally be restricted. This exposed secret can be used to impersonate the client and gain unauthorized access to its associated service account permissions.13h