Vulnerability  ·  2026-09-28

Contrast confidential-computing runtime: generated policies allow container image substitution (integrity bypass)

VulnerabilityMedium impactGlobalCVE-2026-100833
NVD published on 2026-09-27 (VulnCheck): Contrast versions 1.14.0-1.23.1 generate runtime policies that fail to detect all container image substitutions via the image_guest_pull driver due to the missing digest check.
Contrast is a confidential-computing runtime used to protect sensitive/ML workloads on Kubernetes in the public cloud; an integrity-bypass in its policy generation weakens the attestation guarantees AI/ML workloads rely on when running on untrusted infrastructure.
A bad rebase during a Kata Containers update introduced an allow_storage rule accepting storage entries with the image_guest_pull driver without digest verification; an attacker with Kata agent API access can substitute a container image with an exploit payload satisfying remaining policy rules, bypassing the confidential container's integrity guarantees (CVSS 8.2 v3.1).
edgelesssys/contrast 1.14.0 before 1.23.1
Upgrade to contrast 1.23.1. Advisory: https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898
NVD CVE-2026-100833GitHub Security Advisory GHSA-m2qg-wrxv-h898
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →