Contrast 1.20.0 版本中,transit-engine 端点的 ciphertextContainer.UnmarshalJSON 函数存在一个恐慌(panic)漏洞。该函数在切片操作前未对解码后的密文长度进行验证。拥有有效 mesh 证书并已认证的客户端(workload)可通过提交一个过短的 base64 编码密文触发运行时恐慌,导致日志大量输出(log spam)和请求失败,但不会导致进程崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| edgelesssys | contrast | 0 ~ 1.20.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100839 | 8.4 HIGH | Contrast before 1.18.0 AML Injection Remote Code Execution |
| CVE-2026-100833 | 8.2 HIGH | Contrast before 1.23.1 Image Substitution via Policy Generation |
| CVE-2026-100838 | 8.1 HIGH | Contrast before 1.19.1 CopyFile Policy Symlink Subversion |
| CVE-2026-100835 | 7.4 HIGH | Contrast before 1.16.0 Remote Attestation Relay Attack |
| CVE-2025-71425 | 7.3 HIGH | Contrast before 1.8.1 Information Disclosure via Logging |
| CVE-2025-71423 | 7.3 HIGH | Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure |
| CVE-2025-71426 | 7.1 HIGH | Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery |
| CVE-2025-71422 | 5.7 MEDIUM | Contrast before 1.12.1 Insecure LUKS2 Persistent Storage |
| CVE-2026-100837 | 3.7 LOW | Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching |
| CVE-2025-71424 | 3.5 LOW | Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount |
No comments yet