Sceawere
Vulnerability Detail
CVE-2026-100837UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Contrast ImagePuller Registry Suffix Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 1d ago
- Vendor
- edgelesssys
- Product
- contrast
- Attack Type
- Improper Validation of Unsafe Equivalence in Input
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses strings.HasSuffix(hostname, fqdn) without requiring a DNS label boundary, so a registry entry such as [registries."ghcr.io."] is also applied to any host whose name merely ends in that byte sequence, including attacker-registered domains such as evilghcr.io. When an image or layer is pulled from such a sibling domain, the imagepuller sends the configured Authorization header (basic auth, registry token, or identity token), trusts the configured custom CA bundle, follows the configured mirror, and honours insecure-skip-verify (disabling TLS verification) for that host. Image integrity is not affected, as image bytes remain pinned by digest in the policy and are validated after the pull. Configurations that use a leading dot (e.g., [registries.".example.registry"]) are unaffected.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-09-27T02:17:21.937Z",
"pubdate": "2026-09-27T02:17:21.937Z",
"executiveSummary": "Contrast (Edgeless Systems) through version 1.20.0 contains a critical security flaw in its imagepuller component related to registry configuration matching. The vulnerability stems from an unanchored suffix matching logic used within the Config.registryFor function. By failing to enforce DNS label boundaries, the system incorrectly applies registry-specific configurations—including authentication credentials and TLS bypass settings—to unauthorized domains that share a suffix with legitimate, configured registries.\nThe vulnerability allows an attacker to manipulate the imagepuller into leaking sensitive authentication tokens or credentials by inducing requests to attacker-controlled domains (e.g., 'evilghcr.io') that match the suffix of an authorized registry (e.g., 'ghcr.io.'). When the imagepuller is triggered to interact with these malicious domains, it may transmit configured Authorization headers, utilize custom CA bundles, or disable TLS verification as dictated by the misapplied configuration. This poses a significant risk to organizational supply chain integrity and credential confidentiality. While image integrity remains protected via digest pinning and post-pull verification, the exposure of secrets and potential for man-in-the-middle attacks via TLS verification bypass present high-risk security implications.",
"technicalDetails": "The root cause of this vulnerability lies in the improper implementation of hostname matching within the imagepuller's Config.registryFor function. Specifically, the function strips a single trailing dot from the registry entry and subsequently executes a strings.HasSuffix(hostname, fqdn) check. This implementation is fundamentally flawed because it lacks a DNS label boundary requirement. By failing to verify that the suffix match occurs at a legitimate dot-delimited segment, the function incorrectly validates hostnames that merely share the same trailing byte sequence.\nFor example, a registry configuration defined as [registries.'ghcr.io.'] will be erroneously applied to any domain that ends in 'ghcr.io', such as 'evilghcr.io' or 'myghcr.io'. Because the logic treats these unauthorized domains as trusted members of the configured registry entry, the imagepuller adopts the security context defined for the target registry. This context includes critical security parameters such as Basic Auth credentials, registry tokens, identity tokens, and custom CA bundles.\nThe attack flow follows a predictable pattern: An attacker registers or controls a domain that satisfies the unanchored suffix condition for a highly trusted or frequently used registry configured in Contrast. When the Contrast imagepuller attempts to resolve or pull an image, the misconfigured logic causes it to associate the attacker's domain with the legitimate registry's configuration. Consequently, the puller inadvertently presents sensitive credentials (Basic Auth or Bearer tokens) to the attacker-controlled server. Furthermore, if the legitimate registry configuration included 'insecure-skip-verify', the attacker can perform man-in-the-middle operations without triggering TLS certificate validation errors. This allows for the interception of traffic and the potential distribution of malicious payloads that, while ultimately rejected by the digest verification phase, could be used to probe for other vulnerabilities or exploit metadata in the pull process.\nThis vulnerability affects Contrast versions through 1.20.0. The exploit requires the attacker to influence or predict the targets being processed by the imagepuller, ensuring that the hostnames of interest intersect with the improperly matched suffix. The impact is limited to the leakage of credentials and the circumvention of TLS security policies; it does not compromise the cryptographic verification of image layers, as the final image digest remains enforced by the policy."
}