Sceawere
Vulnerability Detail
CVE-2026-100836UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Contrast Ciphertext UnmarshalJSON Panic
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 1d ago
- Vendor
- edgelesssys
- Product
- contrast
- Attack Type
- Improper Validation of Array Index
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid mesh certificate can trigger a runtime panic by submitting a short base64-encoded ciphertext, causing log spam and request failures without crashing the process.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-27T02:17:21.797Z",
"pubdate": "2026-09-27T02:17:21.797Z",
"executiveSummary": "A runtime panic vulnerability exists in Contrast through version 1.20.0 within the transit-engine component.\nThe vulnerability resides in the ciphertextContainer.UnmarshalJSON function, which fails to adequately validate the length of decoded ciphertext prior to memory slicing operations.\nAn attacker possessing an authenticated workload with a valid mesh certificate can trigger a denial-of-service condition by providing a malformed, short base64-encoded ciphertext string.\nSuccessful exploitation results in process-level log spamming and the subsequent failure of legitimate requests processed by the transit-engine.\nWhile the vulnerability does not result in a full process crash, it effectively degrades system availability and disrupts communication protocols.\nThe vulnerability is limited to authenticated actors who maintain the necessary mesh credentials, precluding unauthorized external exploitation.",
"technicalDetails": "The vulnerability is located within the transit-engine module of the Contrast product, specifically inside the UnmarshalJSON method implementation for the ciphertextContainer object.\nThe root cause is an improper bounds check during the decoding and deserialization process. When the application receives a base64-encoded ciphertext payload, the UnmarshalJSON function proceeds to slice the underlying byte array without verifying that the decoded content meets the minimum length requirements expected by the transit-engine's cryptographic implementation.\nWhen a specially crafted, short base64 payload is submitted, the slice operation attempts to access memory indices that do not exist or are out of bounds for the input buffer, triggering a runtime panic in the Go runtime environment.\nThe attack flow begins when an authenticated workload, utilizing a valid mesh certificate, transmits a request to the affected transit-engine endpoint. The attacker includes the malicious, truncated ciphertext within the JSON payload. Upon receipt, the transit-engine attempts to unmarshal the payload. The function fails to perform input validation on the resulting byte slice before passing it to subsequent logic.\nThe resulting panic leads to immediate execution interruption for that specific goroutine or request context. This behavior manifests as high-frequency log spamming, as the system logs the panic stack traces, further taxing system resources. Because the vulnerability disrupts request handling, the transit-engine becomes unable to process legitimate ciphertexts during the period of active exploitation.\nThis vulnerability is restricted to authenticated entities within the service mesh, requiring a valid certificate to reach the vulnerable endpoint. It does not provide remote code execution (RCE) or memory corruption primitives that could lead to privilege escalation; the impact is strictly limited to an application-level denial-of-service affecting the transit-engine service stability."
}