Panic Vulnerability in Contrast Transit Engine Endpoint by Edgeless Systems
CVE-2026-100836

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100836?

The Contrast product from Edgeless Systems, specifically version 1.20.0, is affected by a panic vulnerability within the transit-engine endpoint. This issue arises in the ciphertextContainer.UnmarshalJSON function, which inadequately validates the length of decoded ciphertexts before performing a slicing operation. As a result, an authenticated user with a valid mesh certificate can trigger a runtime panic by sending a short base64-encoded ciphertext. This leads to log spam and request failures, ultimately impacting the reliability of the service without resulting in a complete application crash.

Affected Version(s)

contrast 0 <= 1.20.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.