Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery
Published Sep 27, 2026
7.1
HIGHCVSS 4.0
EPSS 0.14%
Description
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifest passes validation but whose secret seed is attacker-controlled. If network traffic is redirected from the legitimate Coordinator to the attacker's Coordinator, a workload owner can be impersonated when they either set a new manifest without comparing the returned root CA certificate against the existing one (the default behavior of the contrast CLI) or verify the Coordinator without comparing the root CA certificate against a trusted reference. Under these conditions the attacker can issue certificates that chain back to the rogue Coordinator's root CA and recover arbitrary workload secrets of workloads deployed after the attack. Secrets of the legitimate Coordinator (seed, workload secrets, CA), workload integrity, and certificates chaining to the mesh CA are not affected.
Affected products
-
- Version 0StatusaffectedConstraints<1.4.1
- Version 1.4.1StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Edgelesssys | Contrast | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
github.com/edgelesssys/contrast
Go
Introduced 0 Fixed 1.4.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/edgelesssys/contrast | 0 | 1.4.1 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 30, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (2)
- https://github.com/edgelesssys/contrast/security/advisories/GHSA-vqv5-385r-2hf8 vendor-advisory
- https://www.vulncheck.com/advisories/contrast-before-1.4.1-coordinator-impersonation-via-unauthenticated-recovery third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/edgelesssys/contrast/security/advisories/GHSA-vqv5-385r-2hf8 | vendor-advisory | |
| https://www.vulncheck.com/advisories/contrast-before-1.4.1-coordinator-impersonation-via-unauthenticated-recovery | third-party-advisory |
Change history (0)
No recorded changes yet.