Impact
Contrast through version 1.20.0 and earlier contains a panic in the transit‑engine endpoint when deserializing ciphertextContainer. The function fails to verify that the decoded ciphertext is long enough before slicing, allowing an attacker who has authenticated as a workload with a valid mesh certificate to send a deliberately short base64‑encoded ciphertext. The deserialization then panics, producing repeated log entries and causing the request to fail, but the process remains alive. The weakness is a length‑validation error (CWE‑129).
Affected Systems
Vendors affected are Edgeless Systems, specifically the Contrast product. Versions up to and including 1.20.0 are vulnerable; the issue is documented for Contrast versions 1.20.0 and earlier. Workloads deployed with a mesh certificate in a production or staging environment that can communicate with the transit‑engine endpoint are subject to the exploit.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Because the exploit requires an authenticated workload within the mesh and the service must accept a malformed ciphertext, the likelihood of widespread exploitation is reduced. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The impact manifests as denial of service to the affected endpoint, generating excessive log traffic and failing client requests but not crashing the process, which can degrade service availability and increase operational costs.
OpenCVE Enrichment