{"id":"GHSA-6c87-g9pw-78fx","summary":"Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries","details":"# Summary\n\n`Config.registryFor` selected a per-registry credential / CA / mirror block by checking `strings.HasSuffix(name, fqdn)` after stripping a single trailing dot. \nThe match has no boundary between the configured FQDN and any preceding characters in the request hostname.\nA registry configured as `[registries.\"ghcr.io.\"]` is therefore also applied to any image pulled from a host whose name happens to end in the literal byte sequence `ghcr.io`, \nincluding attacker-registered domains such as `evilghcr.io.` \nThe imagepuller would then send the configured `Authorization` header (basic auth, registry token, or identity token), trust the configured custom CA bundle,\nfollow the configured mirror, or honour `insecure-skip-verify`, on requests to that hostname.\n\n# Prerequisites\n\nFor this to be applicable, an image or layer must be pulled from a \"sibling\" domain ending in one of the FQDNs configured in the imagepuller config.\nThis may occur due to malicious intent or coincidentally.\n\n# Impact\n\n- Authentication header leaks to the sibling registry.\n- If `insecure-skip-verify` is set on an FQDN, TLS will also not be verified for the sibling registry.\n- Mirrors configured for an FQDN will also be used with the sibling registry.\n\n## Not impacted\n\nImage integrity is **not** impacted. Image bytes remain pinned by digest in the policy and are validated after the pull.\nThis advisory does not allow code substitution.\n\n# Workaround\n\n- If possible, configure explicit subdomains in the imagepuller config. A configuration for `[registries.\".example.registry\"]` is unaffected, only `[registries.\"example.registry\"]` is potentially affected.\n- Audit images and layers configured in the deployment for the existence of sibling domains.\n\n# Patches\n\nAfter this patch, registry matches are determined by exact label equality instead of suffix matching.\nEach `.`-separated part of the FQDN must be an exact match with the corresponding label in the image reference.\n\n# Severity\n\n- `AV:N` because the leak is over the network to a registry under the attacker's control. \n- `AC:H` because exploitation requires the operator to have configured a registry FQDN without a leading `.` AND the attacker to control a sibling-suffix domain that the deployment will pull from.\n- `PR:N` for the eventual recipient. \n- `S:U` because impact stays in the imagepuller. \n- `C:L` for credential leak (no integrity / availability impact).","aliases":["CVE-2026-100837","GO-2026-5865"],"modified":"2026-09-27T11:55:37.747659462Z","published":"2026-07-01T18:43:55Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-07-01T18:43:55Z","nvd_published_at":null,"cwe_ids":["CWE-1289"]},"references":[{"type":"WEB","url":"https://github.com/edgelesssys/contrast/security/advisories/GHSA-6c87-g9pw-78fx"},{"type":"WEB","url":"https://github.com/edgelesssys/contrast/commit/10826b1d82613025767fb094e8aa51a7dcfbd2a1"},{"type":"PACKAGE","url":"https://github.com/edgelesssys/contrast"},{"type":"WEB","url":"https://github.com/edgelesssys/contrast/releases/tag/v1.21.0"}],"affected":[{"package":{"name":"github.com/edgelesssys/contrast","ecosystem":"Go","purl":"pkg:golang/github.com/edgelesssys/contrast"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.21.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-6c87-g9pw-78fx/GHSA-6c87-g9pw-78fx.json","last_known_affected_version_range":"\u003c= 1.20.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}