github.com/edgelesssys/contrast
Deploy and manage confidential containers on Kubernetes
Activity
- Latest release
- Jul 01, 2026
- Total releases
- 50
- Cadence
- ~14 days
- Last 12 months
- 12
Reach
- Stars
- 301
Details
- First release
- Feb 02, 2024
| Version | Released | |
|---|---|---|
v1.22.0
minor
|
v1.22.0
minor
Dependencies (36)
+ 28 more |
|
v1.21.0
minor
|
v1.21.0
minor
Dependencies (36)
+ 28 more |
|
v1.20.0
minor
2 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v1.20.0
minor
Dependencies (36)
+ 28 more |
|
v1.19.1
patch
2 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v1.19.1
patch
Dependencies (36)
+ 28 more |
|
v1.19.0
minor
3 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.19.0
minor
Dependencies (36)
+ 28 more |
|
v1.18.0
minor
3 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.18.0
minor
Dependencies (35)
+ 27 more |
|
v1.17.0
minor
4 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev |
v1.17.0
minor
Dependencies (35)
+ 27 more |
|
v1.16.0
minor
4 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev |
v1.16.0
minor
Dependencies (33)
+ 25 more |
|
v1.15.1
patch
4 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev |
v1.15.1
patch
Dependencies (33)
+ 25 more |
|
v1.15.0
minor
4 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev |
v1.15.0
minor
Dependencies (33)
+ 25 more |
|
v1.14.0
minor
4 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev |
v1.14.0
minor
Dependencies (33)
+ 25 more |
|
v1.13.0
minor
4 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev |
v1.13.0
minor
Dependencies (33)
+ 25 more |
|
v1.12.2
patch
4 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev |
v1.12.2
patch
Dependencies (31)
+ 23 more |
|
v1.12.1
patch
5 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-3920
GHSA-vxg3-w9rv-rhr2
Sep 08, 2025
Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.12.2
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.1
patch
Dependencies (31)
+ 23 more |
|
v1.12.0
minor
6 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3920
GHSA-vxg3-w9rv-rhr2
Sep 08, 2025
Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.12.2
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.0
minor
Dependencies (31)
+ 23 more |
|
v1.11.0
minor
6 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3920
GHSA-vxg3-w9rv-rhr2
Sep 08, 2025
Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.12.2
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.0
minor
Dependencies (30)
+ 22 more |
|
v1.10.0
minor
6 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3920
GHSA-vxg3-w9rv-rhr2
Sep 08, 2025
Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.12.2
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.0
minor
Dependencies (30)
+ 22 more |
|
v1.9.1
patch
6 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3920
GHSA-vxg3-w9rv-rhr2
Sep 08, 2025
Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.12.2
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.9.1
patch
Dependencies (30)
+ 22 more |
|
v1.9.0
minor
7 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3920
GHSA-vxg3-w9rv-rhr2
Sep 08, 2025
Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.12.2
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.9.0
minor
Dependencies (30)
+ 22 more |
|
v1.8.1
patch
6 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.8.1
patch
Dependencies (30)
+ 22 more |
|
v1.8.0
minor
7 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev |
v1.8.0
minor
Dependencies (30)
+ 22 more |
|
v1.7.0
minor
7 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev |
v1.7.0
minor
Dependencies (28)
+ 20 more |
|
v1.6.0
minor
7 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev |
v1.6.0
minor
Dependencies (28)
+ 20 more |
|
v1.5.1
patch
7 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.1
patch
Dependencies (27)
+ 19 more |
|
v1.5.0
minor
7 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.0
minor
Dependencies (27)
+ 19 more |
|
v1.4.1
patch
7 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (27)
+ 19 more |
|
v1.4.0
minor
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (27)
+ 19 more |
|
v1.3.0
minor
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.0
minor
Dependencies (27)
+ 19 more |
|
v1.2.1
patch
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (27)
+ 19 more |
|
v1.2.0
minor
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (27)
+ 19 more |
|
v1.1.1
patch
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.1
patch
Dependencies (27)
+ 19 more |
|
v1.1.0
minor
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (27)
+ 19 more |
|
v1.0.0
major
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.0
major
Dependencies (27)
+ 19 more |
|
v0.9.0
minor
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.9.0
minor
Dependencies (27)
+ 19 more |
|
v0.8.1
patch
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.8.1
patch
Dependencies (24)
+ 16 more |
|
v0.8.0
minor
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.8.0
minor
Dependencies (24)
+ 16 more |
|
v0.7.3
patch
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.7.3
patch
Dependencies (23)
+ 15 more |
|
v0.7.2
patch
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.7.2
patch
Dependencies (23)
+ 15 more |
|
v0.7.1
patch
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.7.1
patch
Dependencies (23)
+ 15 more |
|
v0.7.0
minor
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.7.0
minor
Dependencies (23)
+ 15 more |
|
v0.6.1
patch
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.1
patch
Dependencies (19)
+ 11 more |
|
v0.6.0
minor
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.0
minor
Dependencies (19)
+ 11 more |
|
v0.5.1
patch
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.1
patch
Dependencies (17)
+ 9 more |
|
v0.5.0
minor
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (16)
+ 8 more |
|
v0.4.1
patch
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.1
patch
Dependencies (15)
+ 7 more |
|
v0.4.0
minor
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (15)
+ 7 more |
|
v0.3.0
minor
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.3.0
minor
Dependencies (15)
+ 7 more |
|
v0.2.0
minor
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.2.0
minor
Dependencies (15)
+ 7 more |
|
v0.1.1
patch
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.1.1
patch
Dependencies (14)
+ 6 more |
|
v0.1.0
initial
8 CVEs
GO-2026-5864
GHSA-3ccm-4qq2-5wrp
Jul 07, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast Constrata's coordinator transit engine Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5865
GHSA-6c87-g9pw-78fx
Jul 07, 2026
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast Fixed in
1.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-5624
GHSA-rh99-wc69-c255
Jun 25, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast Fixed in
1.19.1
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4863
GHSA-g9ww-x58f-9g6m
Apr 02, 2026
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast Fixed in
1.18.0
References Updated Apr 02, 2026 · Source: OSV.dev
GO-2025-4078
GHSA-f5p4-p5q5-jv3h
Nov 05, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3807
GHSA-phhq-63jg-fp7r
Jul 28, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast Fixed in
1.9.1
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3718
GHSA-h5f8-crrq-4pw8
May 29, 2025
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast Fixed in
1.8.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3455
GHSA-vqv5-385r-2hf8
Feb 05, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast Fixed in
1.4.1
Updated Mar 03, 2026 · Source: OSV.dev |
v0.1.0
initial
Dependencies (14)
+ 6 more |