CVE-2025-71423: Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure

Published Sep 27, 2026
·
Updated

Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list permission on pods/logs. Because workload secrets are used for encrypted storage and Vault integration, those must also be considered compromised. This is a regression of GHSA-h5f8-crrq-4pw8.

Affected Software

1 affected component
Edgelesssys Contrast>=1.9.0<1.12.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Edgelesssys Contrast to a version that resolves this vulnerability.

    Fixed in 1.12.2

Event History

Sep 27, 2026
CVE Published
via MITRE·01:28 AM
Data Sourced
via MITRE·01:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can access the exposed workload secrets?

Any Kubernetes user with get or list permission on pods/logs can access the initializer's INFO-level output containing the full NewMeshCert response and workload secret.

2

What must an attacker be able to do to exploit this issue?

The attacker needs Kubernetes permission to get or list pod logs. No user interaction is required.

3

Which deployments are affected?

Edgelesssys Contrast versions from 1.9.0 up to, but not including, 1.12.2 are affected.

4

What assets should be treated as compromised if vulnerable logs were accessible?

Treat the workload secrets as compromised. Because those secrets are used for encrypted storage and Vault integration, the associated encrypted-storage and Vault integration secrets must also be considered compromised.

5

How can I determine whether my environment is affected?

Check whether Contrast is running a version in the affected range and inspect initializer standard-output logs for full NewMeshCert responses. Also identify Kubernetes users or identities that have get or list access to pods/logs, as they could have accessed the disclosed secrets.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203