What happened
NVD published on 2026-09-27 (VulnCheck): Contrast versions 1.14.0-1.23.1 generate runtime policies that fail to detect all container image substitutions via the image_guest_pull driver due to the missing digest check.
Why it matters
Contrast is a confidential-computing runtime used to protect sensitive/ML workloads on Kubernetes in the public cloud; an integrity-bypass in its policy generation weakens the attestation guarantees AI/ML workloads rely on when running on untrusted infrastructure.
Attack vector
A bad rebase during a Kata Containers update introduced an allow_storage rule accepting storage entries with the image_guest_pull driver without digest verification; an attacker with Kata agent API access can substitute a container image with an exploit payload satisfying remaining policy rules, bypassing the confidential container's integrity guarantees (CVSS 8.2 v3.1).
Affected systems
edgelesssys/contrast 1.14.0 before 1.23.1
Mitigation
Upgrade to contrast 1.23.1. Advisory: https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898