Suffix Matching Vulnerability in Contrast by Edgeless Systems
CVE-2026-100837

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100837?

The vulnerability in Contrast by Edgeless Systems allows exploitation through unanchored suffix matching in the imagepuller component. Specifically, when selecting configurations per registry, the mechanism can incorrectly accept registry entries like [registries."ghcr.io."] as valid for domains that simply end with the specified suffix. This flaw permits unauthorized domains, including those registered by attackers, to initiate image pulls while utilizing the configured Authorization headers and trust settings, potentially leading to credential leaks. It’s essential to note that configurations using a leading dot remain unaffected, and image integrity remains secure as bytes are validated post-pull.

Affected Version(s)

contrast 0 <= 1.20.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
.