Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100833— Contrast before 1.23.1 Image Substitution via Policy Generation

Quick assessment

Affected
edgelesssys contrast
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Contrast(edgelesssys/contrast)在 1.14.0 至 1.23.1 版本(不含 1.23.1)中生成的运行时策略未能检测所有容器镜像替换行为。在 Kata Containers 的一次更新中,由于错误的 rebase 操作,意外引入了一条 规则,该规则允许使用 驱动程序的存储条目,且未验证镜像摘要(image digest)。因此,在 Contrast 的威胁模型中,例如拥有 Kata 代理 API 访问权限的 Kubernetes 集群管理员,若能确保被替换的镜像满足其余策略规则的要求

CVSS 8.2 · High EPSS 0.23% · P12

Possible ATT&CK Techniques 1 AI

T1608.004 · Drive-by Target
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100833

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Contrast before 1.23.1 Image Substitution via Policy Generation
Source: CVE Program / CVE List V5
Vulnerability Description
Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver without verifying the image digest. An attacker with access to the Kata agent API — for example, a Kubernetes cluster administrator in Contrast's threat model — can therefore substitute a container image with an exploit payload, provided the substituted image satisfies the remaining policy rules, undermining the confidential container's integrity guarantees.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
edgelesssys contrast 1.14.0 ~ 1.23.1 -

II. Public POCs for CVE-2026-100833

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100833

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100833 (1)

Other References for CVE-2026-100833 (1)

Same Patch Batch · edgelesssys · 2026-09-27 · 11 CVEs total

CVE-2026-100839 8.4 HIGH Contrast before 1.18.0 AML Injection Remote Code Execution
CVE-2026-100838 8.1 HIGH Contrast before 1.19.1 CopyFile Policy Symlink Subversion
CVE-2026-100835 7.4 HIGH Contrast before 1.16.0 Remote Attestation Relay Attack
CVE-2025-71425 7.3 HIGH Contrast before 1.8.1 Information Disclosure via Logging
CVE-2025-71423 7.3 HIGH Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure
CVE-2025-71426 7.1 HIGH Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery
CVE-2025-71422 5.7 MEDIUM Contrast before 1.12.1 Insecure LUKS2 Persistent Storage
CVE-2026-100836 4.3 MEDIUM Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer
CVE-2026-100837 3.7 LOW Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching
CVE-2025-71424 3.5 LOW Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount

IV. Related Vulnerabilities

V. Comments for CVE-2026-100833

No comments yet


Leave a comment