
Python PoC for CVE-2026-100835: audits Contrast manifests for AllowedChipIDs/AllowedPIIDs, detects versions, and probes Coordinator endpoints to assess aTLS attestation relay risk.
Python 3 PoC for CVE-2026-100835 — Edgeless Systems Contrast before 1.16.0.
CVE-2026-100835 — Remote attestation relay against Contrast attested TLS (aTLS) (CWE-295). Before 1.16.0, Contrast treated any cryptographically valid TEE attestation report that matched ReferenceValues (firmware TCB, measurements) as sufficient, without binding the report to specific, physically trusted hardware. An attacker who can intercept attestation traffic (CLI ↔ Coordinator or Coordinator ↔ workload) and who controls any compatible TEE (or can extract relay secrets from one host) can relay a report and impersonate the Coordinator or a workload, defeating aTLS identity verification.
Fixed release: 1.16.0 adds manifest fields AllowedChipIDs (SEV-SNP) and AllowedPIIDs (TDX); operators must populate them with IDs from physically audited hosts. Empty lists still accept any chip/PIID — relay remains possible until lists are set.
CVSS 4.0: VulnCheck 9.1 CRITICAL (AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N).
Advisories: GHSA-hjgc-jc5v-fw7h, VulnCheck.
PoC page: https://pocbit.org/pocs/cve-2026-100835
Catalog: https://pocbit.org/pocs/
| Vendor / product | Edgeless Systems Contrast |
| Affected | 0 < version < 1.16.0 |
| Component | Remote attestation / aTLS |
| Attack | Relay valid TEE report + MITM |
| Mitigation | Upgrade ≥ 1.16.0 + AllowedChipIDs / AllowedPIIDs |
| CWE | CWE-295 Improper Certificate Validation |
This PoC audits manifests, extracts Contrast versions from manifests/K8s YAML, probes Coordinator HTTP endpoints, and documents the relay chain. It does not perform MITM or TEE forgery (lab-only, authorized use).
pip install -r requirements.txt
python poc.py --manifest manifest.json --contrast-version 1.15.0 --mode manifest
python poc.py -u https://coordinator.example:1313 --manifest manifest.json --mode check
python poc.py -u https://coordinator.example:1313 --mode exploit --print-chain
python poc.py --list targets.example.txt --manifest manifest.json -j 8
python poc.py --k8s deployment.yaml --manifest manifest.json --mode manifest
See manifest.example.json for empty allowlist = relay-config risk.
CVE-2026-100835 PoC: Edgeless Contrast < 1.16.0 remote attestation relay (aTLS identity bypass). Manifest audit for AllowedChipIDs / AllowedPIIDs, version detection, Coordinator probe, relay chain notes. PoCbit
CVE-2026-100835: Contrast 1.16.0 öncesi attestation raporları donanıma bağlanmıyor; MITM + saldırgan TEE ile relay mümkün. PoC: manifest/K8s sürüm analizi, coordinator probe, otomatik exploit yok.
Authorized security research and own deployments only. Relay attacks compromise all mesh/workload secrets — follow vendor incident response if exploitation is suspected.