Contrast 是 Kubernetes 的一个机密计算运行时环境。在 1.19.1 之前的版本中,由 Contrast CLI 生成的 Kata 代理策略在 CopyFile 验证环节存在缺陷,允许对访客(guest)根文件系统执行任意写入操作。如果不受信任的主机上存在恶意进程,并能连接到 Kata 代理的 VSOCK 接口,就可以发起一系列 CopyFile 请求,从而覆盖访客系统中安全关键的文件,或诱使工作负载泄露敏感数据,实质上等同于完全接管访客系统。 对于暂时无法升级的用户,可以通过运行 命令应用等效的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| edgelesssys | contrast | 0 ~ 1.19.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100839 | 8.4 HIGH | Contrast before 1.18.0 AML Injection Remote Code Execution |
| CVE-2026-100833 | 8.2 HIGH | Contrast before 1.23.1 Image Substitution via Policy Generation |
| CVE-2026-100835 | 7.4 HIGH | Contrast before 1.16.0 Remote Attestation Relay Attack |
| CVE-2025-71425 | 7.3 HIGH | Contrast before 1.8.1 Information Disclosure via Logging |
| CVE-2025-71423 | 7.3 HIGH | Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure |
| CVE-2025-71426 | 7.1 HIGH | Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery |
| CVE-2025-71422 | 5.7 MEDIUM | Contrast before 1.12.1 Insecure LUKS2 Persistent Storage |
| CVE-2026-100836 | 4.3 MEDIUM | Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer |
| CVE-2026-100837 | 3.7 LOW | Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching |
| CVE-2025-71424 | 3.5 LOW | Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount |
No comments yet