CVE-2026-100836
Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid mesh certificate can trigger a runtime panic by submitting a short base64-encoded ciphertext, causing log spam and request failures without crashing the process.
| CWE | CWE-129 |
| Vendor | edgelesssys |
| Product | contrast |
| Published | Sep 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for edgelesssys contrast
Be the first to know when new medium vulnerabilities affecting edgelesssys contrast are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Affected Versions
edgelesssys / contrast
0 โค 1.20.0