CVE-2025-71426 Details
Description
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifest passes validation but whose secret seed is attacker-controlled. If network traffic is redirected from the legitimate Coordinator to the attacker's Coordinator, a workload owner can be impersonated when they either set a new manifest without comparing the returned root CA certificate against the existing one (the default behavior of the contrast CLI) or verify the Coordinator without comparing the root CA certificate against a trusted reference. Under these conditions the attacker can issue certificates that chain back to the rogue Coordinator's root CA and recover arbitrary workload secrets of workloads deployed after the attack. Secrets of the legitimate Coordinator (seed, workload secrets, CA), workload integrity, and certificates chaining to the mesh CA are not affected.
A vulnerability exists in Contrast, a confidential-computing runtime for Kubernetes, in versions prior to 1.4.1. The issue arises because a recovering Coordinator does not validate the seed provided by the recovering party. This flaw allows an attacker to create a rogue Coordinator with a manifest that passes validation, but with a secret seed under the attacker's control. If network traffic is redirected from the legitimate Coordinator to the attacker's, a workload owner can be impersonated. This can occur either by setting a new manifest without comparing the returned root CA certificate to the existing one— which is the default behavior of the Contrast CLI—or by verifying the Coordinator without referencing a trusted root CA certificate. Under these conditions, the attacker can issue certificates that link back to the rogue Coordinator's root CA and access arbitrary workload secrets from deployments after the attack. However, this vulnerability does not impact the legitimate Coordinator's secrets (seed, workload secrets, CA), workload integrity, or certificates that chain back to the mesh CA.
Users can update to Contrast version 1.4.1, where this vulnerability has been patched. Additionally, when using the Contrast CLI, verify the Coordinator's root CA certificate against a trusted reference, especially after 'set' or 'verify' calls.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Edgelesssys Contrast | <= 1.4.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion