github.com/edgelesssys/contrast
Go9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/edgelesssys/contrastpage 1 of 1
- CVE-2025-71422MEDIUMCVSS 5.7EG 5.7✓ Fixed in 1.12.12026-09-27
Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume feature is vulnerable to a malicious host supplying a crafted LUKS2 volume to a pod VM. LUKS2 volume metadata is not auth…
- CVE-2025-71423HIGHCVSS 7.3EG 7.3✓ Fixed in 1.12.22026-09-27
Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a …
- CVE-2025-71424LOWCVSS 3.5EG 3.5✓ Fixed in 1.9.12026-09-27
Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is no…
- CVE-2025-71425HIGHCVSS 7.3EG 7.3✓ Fixed in 1.8.12026-09-27
Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installati…
- CVE-2025-71426HIGHCVSS 7.1EG 7.1✓ Fixed in 1.4.12026-09-27
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifes…
- CVE-2026-100836MEDIUMCVSS 4.3EG 4.3✓ Fixed in 1.21.02026-09-27
Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid mesh…
- CVE-2026-100837LOWCVSS 3.7EG 3.7✓ Fixed in 1.21.02026-09-27
Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses strings.HasSuffix(hostname, fqdn) wi…
- CVE-2026-100838HIGHCVSS 8.1EG 8.1✓ Fixed in 1.19.12026-09-27
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root fil…
- CVE-2026-100839HIGHCVSS 8.4EG 8.4✓ Fixed in 1.18.02026-09-27
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untru…
Check whether github.com/edgelesssys/contrast is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/edgelesssys/contrast CVEs against the assets you own.
Book a Demo →