Suffix Matching Vulnerability in Contrast by Edgeless Systems
CVE-2026-100837
6.3MEDIUM
What is CVE-2026-100837?
The vulnerability in Contrast by Edgeless Systems allows exploitation through unanchored suffix matching in the imagepuller component. Specifically, when selecting configurations per registry, the mechanism can incorrectly accept registry entries like [registries."ghcr.io."] as valid for domains that simply end with the specified suffix. This flaw permits unauthorized domains, including those registered by attackers, to initiate image pulls while utilizing the configured Authorization headers and trust settings, potentially leading to credential leaks. It’s essential to note that configurations using a leading dot remain unaffected, and image integrity remains secure as bytes are validated post-pull.
Affected Version(s)
contrast 0 <= 1.20.0
