Panic Vulnerability in Contrast Transit Engine Endpoint by Edgeless Systems
CVE-2026-100836
5.3MEDIUM
What is CVE-2026-100836?
The Contrast product from Edgeless Systems, specifically version 1.20.0, is affected by a panic vulnerability within the transit-engine endpoint. This issue arises in the ciphertextContainer.UnmarshalJSON function, which inadequately validates the length of decoded ciphertexts before performing a slicing operation. As a result, an authenticated user with a valid mesh certificate can trigger a runtime panic by sending a short base64-encoded ciphertext. This leads to log spam and request failures, ultimately impacting the reliability of the service without resulting in a complete application crash.
Affected Version(s)
contrast 0 <= 1.20.0
