{"schema_version":1,"title":"Edgeless Systems Contrast vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 10 vulnerabilities in Edgeless Systems Contrast: 8 in the last 7 days and 10 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100839, was published on 27 September 2026.","url":"https://junglewise.ai/threats/technologies/contrast","json_url":"https://junglewise.ai/threats/technologies/contrast.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/contrast","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":6,"all_time":10,"critical":0,"exploited":0,"last_7_days":8,"last_30_days":8,"last_90_days":10,"last_365_days":10},"latest":[{"cve":"CVE-2026-100839","cvss":8.4,"slug":"cve-2026-100839-contrast-is-a-confidential-computing-runtime-for-kubernetes-in","title":"Edgeless Systems Contrast AML injection in ACPI handler","severity":"high","exploited":false,"published_at":"2026-09-27T02:17:22.23+00:00","url":"https://junglewise.ai/threats/cve-2026-100839-contrast-is-a-confidential-computing-runtime-for-kubernetes-in"},{"cve":"CVE-2026-100838","cvss":8.1,"slug":"cve-2026-100838-contrast-is-a-confidential-computing-runtime-for-kubernetes-in","title":"Edgeless Systems Contrast arbitrary filesystem write in CopyFile policy","severity":"high","exploited":false,"published_at":"2026-09-27T02:17:22.083+00:00","url":"https://junglewise.ai/threats/cve-2026-100838-contrast-is-a-confidential-computing-runtime-for-kubernetes-in"},{"cve":"CVE-2026-100836","cvss":4.3,"slug":"cve-2026-100836-contrast-through-1-20-0-contains-a-panic-vulnerability-in-the","title":"Edgeless Systems Contrast panic in ciphertextContainer.UnmarshalJSON","severity":"medium","exploited":false,"published_at":"2026-09-27T02:17:21.797+00:00","url":"https://junglewise.ai/threats/cve-2026-100836-contrast-through-1-20-0-contains-a-panic-vulnerability-in-the"},{"cve":"CVE-2026-100835","cvss":7.4,"slug":"cve-2026-100835-contrast-before-1-16-0-is-susceptible-to-remote-attestation","title":"Edgeless Systems Contrast remote attestation relay attack","severity":"high","exploited":false,"published_at":"2026-09-27T02:17:21.64+00:00","url":"https://junglewise.ai/threats/cve-2026-100835-contrast-before-1-16-0-is-susceptible-to-remote-attestation"},{"cve":"CVE-2026-100833","cvss":8.2,"slug":"cve-2026-100833-contrast-edgelesssys-contrast-versions-1-14-0-before-1-23-1","title":"Edgeless Systems Contrast runtime policy image substitution in policy generation","severity":"high","exploited":false,"published_at":"2026-09-27T02:17:21.323+00:00","url":"https://junglewise.ai/threats/cve-2026-100833-contrast-edgelesssys-contrast-versions-1-14-0-before-1-23-1"},{"cve":"CVE-2025-71426","cvss":7.1,"slug":"cve-2025-71426-contrast-is-a-confidential-computing-runtime-for-kubernetes-in","title":"Edgeless Systems Contrast Coordinator impersonation via unauthenticated recovery","severity":"high","exploited":false,"published_at":"2026-09-27T02:17:17.16+00:00","url":"https://junglewise.ai/threats/cve-2025-71426-contrast-is-a-confidential-computing-runtime-for-kubernetes-in"},{"cve":"CVE-2025-71425","cvss":7.3,"slug":"cve-2025-71425-contrast-edgeless-systems-before-1-8-1-logs-the-workload-secret","title":"Contrast workload secret information disclosure in logs","severity":"high","exploited":false,"published_at":"2026-09-27T02:17:16.797+00:00","url":"https://junglewise.ai/threats/cve-2025-71425-contrast-edgeless-systems-before-1-8-1-logs-the-workload-secret"},{"cve":"CVE-2025-71422","cvss":5.7,"slug":"cve-2025-71422-contrast-is-a-kubernetes-runtime-for-confidential-containers-in","title":"Edgeless Systems Contrast insecure LUKS2 persistent volume in initializer","severity":"medium","exploited":false,"published_at":"2026-09-27T02:17:11.04+00:00","url":"https://junglewise.ai/threats/cve-2025-71422-contrast-is-a-kubernetes-runtime-for-confidential-containers-in"},{"cvss":4.3,"slug":"edgeless-systems-contrast-panic-in-transit-engine-unmarshaljson-f1fe367f","title":"Edgeless Systems Contrast panic in transit engine UnmarshalJSON","severity":"medium","exploited":false,"published_at":"2026-07-01T18:47:53+00:00","url":"https://junglewise.ai/threats/edgeless-systems-contrast-panic-in-transit-engine-unmarshaljson-f1fe367f"},{"cvss":3.7,"slug":"edgeless-systems-contrast-credential-leak-via-unanchored-suffix-9d4532bc","title":"Edgeless Systems Contrast credential leak via unanchored suffix matching in Imagepuller","severity":"low","exploited":false,"published_at":"2026-07-01T18:43:55+00:00","url":"https://junglewise.ai/threats/edgeless-systems-contrast-credential-leak-via-unanchored-suffix-9d4532bc"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Edgeless Systems Contrast","slug":"contrast","vendor":{"name":"Edgeless Systems","slug":"edgeless-systems","url":"https://junglewise.ai/threats/vendors/edgeless-systems"},"aliases":[],"category":"infrastructure-software","homepage":"https://www.edgeless.systems/products/contrast/","repo_url":"https://github.com/edgelesssys/contrast","description":"Contrast is an open-source confidential computing platform for deploying and managing containerized workloads in Trusted Execution Environments.","url":"https://junglewise.ai/threats/technologies/contrast"},"most_severe":[{"cve":"CVE-2026-100839","cvss":8.4,"slug":"cve-2026-100839-contrast-is-a-confidential-computing-runtime-for-kubernetes-in","title":"Edgeless Systems Contrast AML injection in ACPI handler","severity":"high","exploited":false,"published_at":"2026-09-27T02:17:22.23+00:00","url":"https://junglewise.ai/threats/cve-2026-100839-contrast-is-a-confidential-computing-runtime-for-kubernetes-in"},{"cve":"CVE-2026-100833","cvss":8.2,"slug":"cve-2026-100833-contrast-edgelesssys-contrast-versions-1-14-0-before-1-23-1","title":"Edgeless Systems Contrast runtime policy image substitution in policy generation","severity":"high","exploited":false,"published_at":"2026-09-27T02:17:21.323+00:00","url":"https://junglewise.ai/threats/cve-2026-100833-contrast-edgelesssys-contrast-versions-1-14-0-before-1-23-1"},{"cve":"CVE-2026-100838","cvss":8.1,"slug":"cve-2026-100838-contrast-is-a-confidential-computing-runtime-for-kubernetes-in","title":"Edgeless Systems Contrast arbitrary filesystem write in CopyFile policy","severity":"high","exploited":false,"published_at":"2026-09-27T02:17:22.083+00:00","url":"https://junglewise.ai/threats/cve-2026-100838-contrast-is-a-confidential-computing-runtime-for-kubernetes-in"},{"cve":"CVE-2026-100835","cvss":7.4,"slug":"cve-2026-100835-contrast-before-1-16-0-is-susceptible-to-remote-attestation","title":"Edgeless Systems Contrast remote attestation relay attack","severity":"high","exploited":false,"published_at":"2026-09-27T02:17:21.64+00:00","url":"https://junglewise.ai/threats/cve-2026-100835-contrast-before-1-16-0-is-susceptible-to-remote-attestation"},{"cve":"CVE-2025-71425","cvss":7.3,"slug":"cve-2025-71425-contrast-edgeless-systems-before-1-8-1-logs-the-workload-secret","title":"Contrast workload secret information disclosure in logs","severity":"high","exploited":false,"published_at":"2026-09-27T02:17:16.797+00:00","url":"https://junglewise.ai/threats/cve-2025-71425-contrast-edgeless-systems-before-1-8-1-logs-the-workload-secret"},{"cve":"CVE-2025-71426","cvss":7.1,"slug":"cve-2025-71426-contrast-is-a-confidential-computing-runtime-for-kubernetes-in","title":"Edgeless Systems Contrast Coordinator impersonation via unauthenticated recovery","severity":"high","exploited":false,"published_at":"2026-09-27T02:17:17.16+00:00","url":"https://junglewise.ai/threats/cve-2025-71426-contrast-is-a-confidential-computing-runtime-for-kubernetes-in"},{"cve":"CVE-2025-71422","cvss":5.7,"slug":"cve-2025-71422-contrast-is-a-kubernetes-runtime-for-confidential-containers-in","title":"Edgeless Systems Contrast insecure LUKS2 persistent volume in initializer","severity":"medium","exploited":false,"published_at":"2026-09-27T02:17:11.04+00:00","url":"https://junglewise.ai/threats/cve-2025-71422-contrast-is-a-kubernetes-runtime-for-confidential-containers-in"},{"cve":"CVE-2026-100836","cvss":4.3,"slug":"cve-2026-100836-contrast-through-1-20-0-contains-a-panic-vulnerability-in-the","title":"Edgeless Systems Contrast panic in ciphertextContainer.UnmarshalJSON","severity":"medium","exploited":false,"published_at":"2026-09-27T02:17:21.797+00:00","url":"https://junglewise.ai/threats/cve-2026-100836-contrast-through-1-20-0-contains-a-panic-vulnerability-in-the"},{"cvss":4.3,"slug":"edgeless-systems-contrast-panic-in-transit-engine-unmarshaljson-f1fe367f","title":"Edgeless Systems Contrast panic in transit engine UnmarshalJSON","severity":"medium","exploited":false,"published_at":"2026-07-01T18:47:53+00:00","url":"https://junglewise.ai/threats/edgeless-systems-contrast-panic-in-transit-engine-unmarshaljson-f1fe367f"},{"cvss":3.7,"slug":"edgeless-systems-contrast-credential-leak-via-unanchored-suffix-9d4532bc","title":"Edgeless Systems Contrast credential leak via unanchored suffix matching in Imagepuller","severity":"low","exploited":false,"published_at":"2026-07-01T18:43:55+00:00","url":"https://junglewise.ai/threats/edgeless-systems-contrast-credential-leak-via-unanchored-suffix-9d4532bc"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}