Contrast, Insecure Image Digest Verification, CVE-2026-100833 (HIGH) -DC-Oct2026-2794

Listen to this Post

Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver without verifying the image digest. An attacker with access to the Kata agent API — for example, a Kubernetes cluster administrator in Contrast’s threat model — can therefore substitute a container image with an exploit payload, provided the substituted image satisfies the remaining policy rules, undermining the confidential container’s integrity guarantees. The vulnerability is classified under CWE-20 (Improper Input Validation) and has been assigned a CVSS 4.0 score of 7.6 (HIGH) by VulnCheck. The affected component is the policy generation logic that produces runtime policies for confidential containers. The issue stems from an accidental of an `allow_storage` rule during a Kata Containers update, which inappropriately permits storage entries using the `image_guest_pull` driver without enforcing image digest verification. This vulnerability allows an attacker who already possesses access to the Kata agent API to replace legitimate container images with arbitrary payloads. The attack can be launched remotely, and no exploit is publicly available at the time of disclosure. The flaw effectively breaks the integrity guarantees of confidential containers by allowing unauthorized image substitution. Organizations using Contrast for confidential computing workloads are at risk if they have not upgraded to version 1.23.1 or later. The vulnerability was published to the NVD on September 26, 2026, and the source is VulnCheck. The CVSS vector string is CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N. This indicates a high impact on confidentiality and integrity, with a low attack complexity but requiring specific preconditions. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. Administrators should prioritize patching to maintain the security posture of their confidential computing environments.

DailyCVE Form:

Platform: Contrast
Version: 1.14.0-1.23.1
Vulnerability : Digest Bypass
Severity: HIGH
date: 2026-09-26

Prediction: 2026-10-15

What Undercode Say:

Check current Contrast version
contrast --version
Verify policy generation configuration
kubectl get configmap contrast-policy -o yaml
Inspect allow_storage rules
grep -r "allow_storage" /etc/contrast/policies/

Exploit: (Educational Purposes!)

Example: Substituting a container image via Kata agent API
Requires access to the Kata agent API endpoint
curl -X POST http://<kata-agent>:<port>/storage \
-H "Content-Type: application/json" \
-d '{
"driver": "image_guest_pull",
"source": "malicious-image:latest",
"digest": ""
}'

Protection: from this CVE

Upgrade Contrast to version 1.23.1 or later
helm upgrade contrast edgelesssys/contrast --version 1.23.1
Or using kubectl
kubectl apply -f https://github.com/edgelesssys/contrast/releases/download/v1.23.1/contrast.yaml

Impact: Container image substitution leading to compromised confidential container integrity.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top