CVE-2026-100836: Edgelesssys Contrast

Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid mesh certificate can trigger a runtime panic by submitting a short base64-encoded ciphertext, causing log spam and request failures without crashing the process.

Affected products

Published 2026-09-27. Last modified 2026-09-28.