Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 27 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid mesh certificate can trigger a runtime panic by submitting a short base64-encoded ciphertext, causing log spam and request failures without crashing the process. | |
| Title | Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer | |
| Weaknesses | CWE-129 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-27T01:29:58.070Z
Reserved: 2026-09-26T23:23:03.410Z
Link: CVE-2026-100836
No data.
Status : Received
Published: 2026-09-27T02:17:21.797
Modified: 2026-09-27T02:17:21.797
Link: CVE-2026-100836
No data.
OpenCVE Enrichment
Updated: 2026-09-27T03:30:20Z