go

github.com/edgelesssys/contrast

View on go registry
18 Total advisories
18 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/edgelesssys/contrast is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
Go

CVE-2026-100836

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast

MEDIUM 4.3
Go

CVE-2026-100836

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts

UNKNOWN
Go

CVE-2025-71422

Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast

MEDIUM 5.7
Go

CVE-2025-71422

Contrast has insecure LUKS2 persistent storage partitions may be opened and used

UNKNOWN
Go

CVE-2025-71426

Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast

HIGH 7.1
Go

CVE-2025-71426

Contrast's unauthenticated recovery allows Coordinator impersonation

UNKNOWN
Go

CVE-2025-71424

Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast

LOW 3.5
Go

CVE-2025-71424

Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points

UNKNOWN
Go

CVE-2025-71423

Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast

HIGH 7.3
Go

CVE-2025-71423

Contrast leaks workload secrets to logs on INFO level

UNKNOWN
Go

CVE-2025-71425

Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast

HIGH 7.3
Go

CVE-2025-71425

Contrast workload secrets leak to logs on INFO level

UNKNOWN
Go

CVE-2026-100838

Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast

HIGH 8.1
Go

CVE-2026-100838

Contras Affected by CopyFile Policy Subversion via Symlinks

UNKNOWN
Go

CVE-2026-100837

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast

LOW 3.7
Go

CVE-2026-100837

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries

UNKNOWN
Go

CVE-2026-100839

Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast

HIGH 8.4
Go

CVE-2026-100839

Contrast BadAML injection allows arbitrary code execution

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes