Junglewise Threat Intelligence

CVE-2026-12039: Docker Sandboxes DNS-based egress policy bypass

CVE-2026-12039 · Severity: info · CVSS 5.7 · Published 2026-06-18

Technologies: Docker Sandboxes (sbx). Vendors: Docker.

Executive brief

Docker Sandboxes (sbx) is a tool used to run untrusted code in isolated environments with restricted network access. A flaw in how these sandboxes handle DNS requests allowed untrusted code to bypass security rules and send data to external servers. This could lead to sensitive information being leaked from the sandbox even when strict internet restrictions are in place.

Technical details

Docker Sandboxes (sbx) versions 0.13.0 through 0.32.x contain a vulnerability where the per-network embedded DNS server does not consult the configured egress policy. While the sandbox enforces an HTTP/S-only allowlist for direct traffic, it blindly forwards all DNS queries to the host resolver if the network is internet-connected. An attacker with the ability to run code inside a sandbox can encode sensitive data into DNS labels (e.g., data.attacker.com) to exfiltrate information through a DNS covert channel. This bypasses the intended network isolation. The issue is resolved in version 0.33.0, which gates DNS resolution on the network policy.

Affected products

  • Docker Docker Sandboxes (sbx) 0.13.0 to 0.33.0

Timeline

  • 2026-06-17: patched: Version 0.33.0 released with fix.
  • 2026-06-18: disclosed: CVE-2026-12039 published.

References