VYPR

contrast

by Edgelesssys

CVEs (8)

  • CVE-2026-100839HigSep 27, 2026
    risk 0.55cvss 8.4epss —

    Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted host (QEMU) to the guest firmware…

  • CVE-2026-100838HigSep 27, 2026
    risk 0.53cvss 8.1epss —

    Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem. A malicious process on the…

  • CVE-2026-100833HigSep 27, 2026
    risk 0.53cvss 8.2epss —

    Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the…

  • CVE-2026-100835HigSep 27, 2026
    risk 0.48cvss 7.4epss —

    Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was…

  • CVE-2025-71426HigSep 27, 2026
    risk 0.46cvss 7.1epss —

    Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifest passes validation but whose secret…

  • CVE-2025-71423HigSep 27, 2026
    risk 0.40cvss 7.3epss —

    Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to…

  • CVE-2025-71422MedSep 27, 2026
    risk 0.30cvss 5.7epss —

    Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume feature is vulnerable to a malicious host supplying a crafted LUKS2 volume to a pod VM. LUKS2 volume metadata is not authenticated and, with cryptsetup versions…

  • CVE-2026-100836MedSep 27, 2026
    risk 0.28cvss 4.3epss —

    Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid mesh certificate can trigger a runtime panic…