edgelesssys contrast

11 known vulnerabilities in edgelesssys contrast, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-100839 CVSS 8.4 high Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable…
  • CVE-2026-100838 CVSS 8.6 high Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast…
  • CVE-2026-100837 CVSS 6.3 medium Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the…
  • CVE-2026-100836 CVSS 5.3 medium Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that…
  • CVE-2026-100835 CVSS 9.1 critical Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified…
  • CVE-2026-100833 CVSS 7.6 high Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image…
  • CVE-2025-71426 CVSS 7.1 high Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed…
  • CVE-2025-71425 CVSS 8.5 high Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is…
  • CVE-2025-71424 CVSS 5.1 medium Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The…
  • CVE-2025-71423 CVSS 8.5 high Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full…
  • CVE-2025-71422 CVSS 6.9 medium Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume feature is…