VulnSea

edgelesssys has 13 CVEs on record. Disclosure cadence is accelerating: 13 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 11. The median CVSS is 7.1 (high). None have a confirmed exploitation report. Most affected products: contrast (11), github.com/edgelesssys/contrast (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
—
Last 90 days
13 prev 0

Products

  • contrast 11
  • github.com/edgelesssys/contrast 2
13
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

edgelesssys vulnerabilities

CVEs affecting edgelesssys, newest first. Open any entry for full detail, references, and exploit status.

13 CVEsRSS

CVE-2026-100839High· 8.4
today

Contrast is a confidential-computing runtime for Kubernetes

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the unt…

▾ Twilightedgelesssys · contrastvia NVD
CVE-2026-100838High· 8.1
today

Contrast is a confidential-computing runtime for Kubernetes

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root f…

▾ Twilightedgelesssys · contrastvia NVD
CVE-2026-100837Low· 3.7
today

Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller

Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses strings.HasSuffix(hostname, fqdn) …

▾ Sunlitedgelesssys · contrastvia NVD
CVE-2026-100836Medium· 4.3
today

Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing

Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid me…

▾ Sunlitedgelesssys · contrastvia NVD
CVE-2026-100835High· 7.4
today

Contrast before 1.16.0 is susceptible to remote attestation relay attacks

Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of whi…

▾ Twilightedgelesssys · contrastvia NVD
CVE-2026-100833High· 8.2
today

Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions

Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule t…

▾ Twilightedgelesssys · contrastvia NVD
CVE-2025-71426High· 7.1
today

Contrast is a confidential-computing runtime for Kubernetes

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manif…

▾ Twilightedgelesssys · contrastvia NVD
CVE-2025-71425High· 7.3
today

Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug

Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installa…

▾ Twilightedgelesssys · contrastvia NVD
CVE-2025-71424Low· 3.5
today

Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0

Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is …

▾ Sunlitedgelesssys · contrastvia NVD
CVE-2025-71423High· 7.3
today

Edgelesssys Contrast is a confidential-computing runtime for Kubernetes

Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a re…

▾ Twilightedgelesssys · contrastvia NVD
CVE-2025-71422Medium· 5.7
today

Contrast is a Kubernetes runtime for confidential containers

Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume feature is vulnerable to a malicious host supplying a crafted LUKS2 volume to a pod VM. LUKS2 volume metadata is not au…

▾ Sunlitedgelesssys · contrastvia NVD
GHSA-6c87-g9pw-78fxLow· 3.7
2mo ago

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries

▾ Sunlitedgelesssys · github.com/edgelesssys/contrastvia GHSA
GHSA-3ccm-4qq2-5wrpMedium· 4.3
2mo ago

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts

▾ Sunlitedgelesssys · github.com/edgelesssys/contrastvia GHSA
edgelesssys vulnerabilities (CVEs) · VulnSea