Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-100835 — Python PoC for CVE-2026-100835: audits Contrast manifests for AllowedChipIDs/AllowedPIIDs, detects versions, and probes Coordinator endpoints to assess aTLS attestation relay risk. | Kitploit
Tools/GitHubGitHub/murrez/cve-2026-100835
Container SecurityVulnerability AnalysisExploitationInformation GatheringCryptographyPenetration TestingCloud SecurityAuthentication
GitHubmurrez/cve-2026-100835

CVE-2026-100835

Python PoC for CVE-2026-100835: audits Contrast manifests for AllowedChipIDs/AllowedPIIDs, detects versions, and probes Coordinator endpoints to assess aTLS attestation relay risk.

6 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

CVE-2026-100835 — Contrast attestation relay (aTLS)

Python 3 PoC for CVE-2026-100835 — Edgeless Systems Contrast before 1.16.0.

Description (PoCbit / GitHub)

CVE-2026-100835 — Remote attestation relay against Contrast attested TLS (aTLS) (CWE-295). Before 1.16.0, Contrast treated any cryptographically valid TEE attestation report that matched ReferenceValues (firmware TCB, measurements) as sufficient, without binding the report to specific, physically trusted hardware. An attacker who can intercept attestation traffic (CLI ↔ Coordinator or Coordinator ↔ workload) and who controls any compatible TEE (or can extract relay secrets from one host) can relay a report and impersonate the Coordinator or a workload, defeating aTLS identity verification.

Fixed release: 1.16.0 adds manifest fields AllowedChipIDs (SEV-SNP) and AllowedPIIDs (TDX); operators must populate them with IDs from physically audited hosts. Empty lists still accept any chip/PIID — relay remains possible until lists are set.

CVSS 4.0: VulnCheck 9.1 CRITICAL (AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N).

Advisories: GHSA-hjgc-jc5v-fw7h, VulnCheck.

PoC page: https://pocbit.org/pocs/cve-2026-100835

PoCbit

Catalog: https://pocbit.org/pocs/

Vendor / productEdgeless Systems Contrast
Affected0 < version < 1.16.0
ComponentRemote attestation / aTLS
AttackRelay valid TEE report + MITM
MitigationUpgrade ≥ 1.16.0 + AllowedChipIDs / AllowedPIIDs
CWECWE-295 Improper Certificate Validation

This PoC audits manifests, extracts Contrast versions from manifests/K8s YAML, probes Coordinator HTTP endpoints, and documents the relay chain. It does not perform MITM or TEE forgery (lab-only, authorized use).

Usage

pip install -r requirements.txt

python poc.py --manifest manifest.json --contrast-version 1.15.0 --mode manifest
python poc.py -u https://coordinator.example:1313 --manifest manifest.json --mode check
python poc.py -u https://coordinator.example:1313 --mode exploit --print-chain
python poc.py --list targets.example.txt --manifest manifest.json -j 8
python poc.py --k8s deployment.yaml --manifest manifest.json --mode manifest

See manifest.example.json for empty allowlist = relay-config risk.

GitHub About (EN)

CVE-2026-100835 PoC: Edgeless Contrast < 1.16.0 remote attestation relay (aTLS identity bypass). Manifest audit for AllowedChipIDs / AllowedPIIDs, version detection, Coordinator probe, relay chain notes. PoCbit

Özet (TR)

CVE-2026-100835: Contrast 1.16.0 öncesi attestation raporları donanıma bağlanmıyor; MITM + saldırgan TEE ile relay mümkün. PoC: manifest/K8s sürüm analizi, coordinator probe, otomatik exploit yok.

Legal

Authorized security research and own deployments only. Relay attacks compromise all mesh/workload secrets — follow vendor incident response if exploitation is suspected.

Download Tool