CVE-2026-100837 Overview
CVE-2026-100837 is a credential disclosure vulnerability in Contrast by Edgeless Systems through version 1.20.0. The imagepuller component performs unanchored suffix matching when selecting per-registry configuration. The Config.registryFor function strips a trailing dot and calls strings.HasSuffix(hostname, fqdn) without enforcing a DNS label boundary. An attacker who registers a sibling domain such as evilghcr.io can receive credentials configured for ghcr.io, including basic auth headers, registry tokens, custom CA trust, and insecure-skip-verify settings. Image integrity is preserved because image bytes are pinned by digest and validated after the pull.
Critical Impact
Attacker-controlled sibling domains receive registry credentials, authorization headers, and trust configuration intended for legitimate registries, enabling credential theft and TLS verification bypass.
Affected Products
- Edgeless Systems Contrast through 1.20.0
- imagepuller component using Config.registryFor suffix matching
- Deployments using registry configuration entries without a leading dot (for example [registries."ghcr.io."])
Discovery Timeline
- 2026-09-27 - CVE-2026-100837 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100837
Vulnerability Analysis
The vulnerability is an improper matching flaw [CWE-1289] in how Contrast resolves per-registry configuration during image pulls. The imagepuller strips one trailing dot from the configured fully qualified domain name (FQDN) and performs a byte-level suffix comparison against the target hostname. The comparison does not verify that the match aligns with a DNS label boundary (a dot separator or the start of the string).
A registry entry declared as [registries."ghcr.io."] therefore matches any hostname whose string representation ends with ghcr.io, including attacker-registered domains such as evilghcr.io. When Contrast pulls an image or layer from the attacker-controlled host, it applies the configured Authorization header, custom certificate authority (CA) bundle, mirror redirection, and insecure-skip-verify TLS setting. Image bytes remain pinned by digest in the policy, so content integrity is unaffected. Credential confidentiality and transport trust are not.
Root Cause
The root cause is unanchored suffix matching in Config.registryFor. The function uses strings.HasSuffix on hostnames without requiring that the matched portion begin at a DNS label boundary. The implementation also strips only a single trailing dot, which does not normalize the comparison to a safe canonical form.
Attack Vector
An attacker registers a domain that ends with the byte sequence of a configured registry FQDN, for example evilghcr.io against a ghcr.io configuration. The attacker then induces or waits for the imagepuller to resolve a reference pointing to the attacker domain. Because the policy still validates the image digest after download, the attacker does not need to serve matching content. The attacker captures the leaked Authorization header, which may contain basic authentication credentials, a registry access token, or an identity token. Disabled TLS verification further exposes the request to passive interception.
See the GitHub Security Advisory GHSA-6c87-g9pw-78fx and the VulnCheck advisory for technical details.
Detection Methods for CVE-2026-100837
Indicators of Compromise
- Image pull requests from Contrast nodes to hostnames that share a trailing substring with configured registries but are not the registry itself (for example evilghcr.io versus ghcr.io).
- Outbound HTTPS requests from imagepuller carrying Authorization headers to unexpected destination domains.
- TLS connections from Contrast workloads where certificate validation is skipped or where an unexpected custom CA chain is presented.
Detection Strategies
- Audit Contrast configuration files for [registries."..."] entries whose keys do not begin with a leading dot, which are the vulnerable pattern.
- Compare image reference hostnames resolved by imagepuller against the exact FQDN list of approved registries using label-boundary matching rather than substring matching.
- Review egress logs and proxy telemetry for image or layer requests to domains that end with but do not equal a known registry FQDN.
Monitoring Recommendations
- Alert on DNS resolutions and NetFlow records from Contrast nodes to newly observed domains that share suffixes with configured registries.
- Monitor registry audit logs for authentication attempts from unexpected source addresses that could indicate credential replay after a leak.
- Instrument the container runtime to log the full destination host for every image pull and correlate against the approved registry allowlist.
How to Mitigate CVE-2026-100837
Immediate Actions Required
- Inventory all Contrast deployments running version 1.20.0 or earlier and identify registry configuration blocks lacking a leading dot.
- Rotate any registry credentials, access tokens, and identity tokens that have been configured in imagepuller on affected deployments.
- Restrict egress from Contrast nodes to an explicit allowlist of registry FQDNs to block pulls from attacker-controlled sibling domains.
Patch Information
Upgrade to a Contrast release later than 1.20.0 that addresses the suffix-matching flaw. Refer to the GitHub Security Advisory GHSA-6c87-g9pw-78fx for the fixed version and upgrade guidance from Edgeless Systems.
Workarounds
- Rewrite registry configuration keys to use a leading dot (for example [registries.".ghcr.io"]), which the advisory states are unaffected.
- Remove any insecure-skip-verify flags from registry entries to retain TLS validation even if credentials are misrouted.
- Enforce network-layer restrictions so that imagepuller can only resolve and connect to the exact approved registry hostnames.
# Configuration example: use a leading-dot form that is not vulnerable
# Vulnerable form (do not use):
# [registries."ghcr.io."]
# authHeader = "Basic ..."
# Safe form per the advisory:
[registries.".ghcr.io"]
authHeader = "Basic ..."
# Do not set insecureSkipVerify = true
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.