18 Total advisories
18 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/edgelesssys/contrast is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-100836
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast
MEDIUM 4.3
CVE-2026-100836
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
UNKNOWN
CVE-2025-71422
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast
MEDIUM 5.7
CVE-2025-71422
Contrast has insecure LUKS2 persistent storage partitions may be opened and used
UNKNOWN
CVE-2025-71426
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast
HIGH 7.1
CVE-2025-71426
Contrast's unauthenticated recovery allows Coordinator impersonation
UNKNOWN
CVE-2025-71424
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast
LOW 3.5
CVE-2025-71424
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points
UNKNOWN
CVE-2025-71423
Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast
HIGH 7.3
CVE-2025-71423
Contrast leaks workload secrets to logs on INFO level
UNKNOWN
CVE-2025-71425
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast
HIGH 7.3
CVE-2025-71425
Contrast workload secrets leak to logs on INFO level
UNKNOWN
CVE-2026-100838
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast
HIGH 8.1
CVE-2026-100838
Contras Affected by CopyFile Policy Subversion via Symlinks
UNKNOWN
CVE-2026-100837
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast
LOW 3.7
CVE-2026-100837
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries
UNKNOWN
CVE-2026-100839
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast
HIGH 8.4
CVE-2026-100839
Contrast BadAML injection allows arbitrary code execution
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes