CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100837

LOWCVSS 3.7NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses strings.HasSuffix(hostname, fqdn) without requiring a DNS label boundary, so a registry entry suc

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100837 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100837

LOWCVSS 3.7NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses strings.HasSuffix(hostname, fqdn) without requiring a DNS label boundary, so a registry entry suc

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]