CVE-2025-71423 Details
Description
Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list permission on pods/logs. Because workload secrets are used for encrypted storage and Vault integration, those must also be considered compromised. This is a regression of GHSA-h5f8-crrq-4pw8.
A vulnerability in Edgelesssys Contrast, a confidential-computing runtime for Kubernetes, has been identified in versions 1.9.0 prior to 1.12.2. The issue arises because the initializer logs the complete NewMeshCert response, which includes the workload secret, to standard output at the INFO level. This logging behavior exposes workload secrets to any Kubernetes user with 'get' or 'list' permission on pods/logs. Since workload secrets are utilized for encrypted storage and Vault integration, those aspects must also be considered compromised. This vulnerability represents a regression of a previously addressed issue.
Users can upgrade to Edgelesssys Contrast version 1.12.2 or 1.13.0 to address this vulnerability. However, since the workload secrets are compromised, it is necessary to initialize Contrast from scratch.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Edgelesssys Contrast | >= 1.9.0, < 1.12.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion