Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-71423 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list permission on pods/logs. Because workload secrets are used for encrypted storage and Vault integration, those must also be considered compromised. This is a regression of GHSA-h5f8-crrq-4pw8.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-532Insertion of Sensitive Information into Log File[email protected]

Affected Products

ProductVersions
Edgelesssys Contrast
>= 1.9.0, < 1.12.2 (semver)

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • Upgrade: v1.12.2moderate effort
  • Workaround:moderate effort

    Reinitialize the Contrast cluster and disable logging.

Change History

2 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-71423
NVD Published Date:
Sep 27, 2026
NVD Last Modified:
Sep 28, 2026
Source:
[email protected]