CVE-2026-100836 Details
Description
Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid mesh certificate can trigger a runtime panic by submitting a short base64-encoded ciphertext, causing log spam and request failures without crashing the process.
A panic vulnerability has been identified in Edgeless Systems Contrast versions through 1.20.0. The issue resides in the transit-engine endpoint's 'ciphertextContainer.UnmarshalJSON' function, which improperly validates the length of decoded ciphertext before slicing. This vulnerability can be exploited by an authenticated workload with a valid mesh certificate, allowing it to send a short base64-encoded ciphertext. The resulting runtime panic causes log spam and request failures, creating a soft denial-of-service condition on the transit-engine endpoint without crashing the Coordinator process.
To address this vulnerability, the 'UnmarshalJSON' function should be modified to validate the length of the decoded ciphertext before slicing. The recommended change is to check that the ciphertext is at least 12 bytes long before extracting the nonce. Additionally, a unit test should be added to ensure that the function correctly handles short ciphertexts by returning a structured error instead of panicking.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/edgelesssys/contrast/security/advisories/GHSA-3ccm-4qq2-5wrp | CISA-ADP | AdvisoryExploitTechnical AnalysisVendor |
| https://github.com/edgelesssys/contrast/security/advisories/GHSA-3ccm-4qq2-5wrp | [email protected] | AdvisoryExploitTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/edgeless-systems-contrast-through-1.20.0-denial-of-service-via-ciphertextcontainer | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-129 | Improper Validation of Array Index | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Edgeless Systems Contrast | <= 1.20.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion