Contrast(Edgeless Systems 公司旗下产品)在 1.20.0 及更早版本中,在 imagepuller(镜像拉取器)选择每注册表(per-registry)配置时,使用了未锚定的后缀匹配逻辑。具体而言,Config.registryFor 函数仅剥离一个末尾的点号( ),然后调用 strings.HasSuffix(hostname, fqdn) 进行后缀匹配,但未要求 DNS 标签边界。因此,例如 [registries."ghcr.io."] 这样的注册表配置条目,不仅适用于 ghcr.i
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| edgelesssys | contrast | 0 ~ 1.20.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100839 | 8.4 HIGH | Contrast before 1.18.0 AML Injection Remote Code Execution |
| CVE-2026-100833 | 8.2 HIGH | Contrast before 1.23.1 Image Substitution via Policy Generation |
| CVE-2026-100838 | 8.1 HIGH | Contrast before 1.19.1 CopyFile Policy Symlink Subversion |
| CVE-2026-100835 | 7.4 HIGH | Contrast before 1.16.0 Remote Attestation Relay Attack |
| CVE-2025-71425 | 7.3 HIGH | Contrast before 1.8.1 Information Disclosure via Logging |
| CVE-2025-71423 | 7.3 HIGH | Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure |
| CVE-2025-71426 | 7.1 HIGH | Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery |
| CVE-2025-71422 | 5.7 MEDIUM | Contrast before 1.12.1 Insecure LUKS2 Persistent Storage |
| CVE-2026-100836 | 4.3 MEDIUM | Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer |
| CVE-2025-71424 | 3.5 LOW | Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount |
No comments yet