<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:edgeless_systems:contrast:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aedgeless_systemscontrast/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 27 Sep 2026 03:03:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aedgeless_systemscontrast/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-100833: Insecure Image Digest Verification in Edgeless Systems Contrast</title><link>https://feed.craftedsignal.io/briefs/2026-09-contrast-digest-vulnerability/</link><pubDate>Sun, 27 Sep 2026 03:03:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-contrast-digest-vulnerability/</guid><description>Edgeless Systems Contrast versions 1.14.0 to 1.23.1 contain an insecure runtime policy configuration that allows attackers with Kata agent API access to substitute container images by bypassing digest verification.</description><content:encoded><![CDATA[<p>Contrast (edgelesssys/contrast) versions 1.14.0 through 1.23.0 are vulnerable to a security policy flaw that undermines the integrity of confidential containers. The issue stems from an accidental introduction of an allow_storage rule during a Kata Containers update, which inappropriately permits storage entries using the image_guest_pull driver without enforcing image digest verification. This vulnerability allows an attacker who already possesses access to the Kata agent API to replace legitimate container images with arbitrary payloads. Because the policy fails to validate the digest, the Kata runtime accepts the unauthorized image substitution, effectively neutralizing the confidential container protection mechanisms. This flaw is particularly relevant for Kubernetes environments where the agent API may be accessible to cluster administrators or other privileged actors within the threat model.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the execution of unauthorized code within a confidential container environment, undermining the integrity guarantees provided by the Edgeless Systems Contrast solution. This effectively permits a sandbox escape or privilege escalation within the container lifecycle management, potentially impacting the confidentiality and integrity of all data processed within the affected confidential container workloads.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade Edgeless Systems Contrast to version 1.23.1 or later immediately to apply the corrected runtime policy logic that enforces strict digest verification.</li>
<li>Audit Kubernetes cluster RBAC configurations to restrict access to the Kata agent API, limiting the potential pool of actors who could leverage this vulnerability.</li>
<li>Review current container deployment pipelines to ensure that integrity labels and image digests are strictly enforced at the orchestrator level, providing a layer of defense-in-depth while patches are deployed.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cloud-security</category><category>confidential-computing</category></item></channel></rss>