PT-2026-99456 · Contrast · Contrast

CVE-2026-100836

·

Published

2026-07-01

·

Updated

2026-09-28

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Contrast versions prior to 1.20.1
Description A panic occurs in the ciphertextContainer.UnmarshalJSON() function within the 'transit-engine' endpoint. The issue arises because the function fails to validate the length of the decoded ciphertext before performing a slicing operation. An authenticated workload possessing a valid mesh certificate can trigger this runtime panic by submitting a short base64-encoded ciphertext, which results in request failures and log spam, although the process does not crash.
Recommendations Update to version 1.20.1 or later.

Exploit

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100836
GHSA-3CCM-4QQ2-5WRP
GO-2026-5864

Affected Products

Contrast