Medium severity4.3NVD Advisory· Published Sep 27, 2026
CVE-2026-100836
CVE-2026-100836
Description
Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid mesh certificate can trigger a runtime panic by submitting a short base64-encoded ciphertext, causing log spam and request failures without crashing the process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.20.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.