CVE-2025-71424: Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount

Published Sep 27, 2026
·
Updated

Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is not handled specially by Kubernetes, but containerd adds a mount point for it when Kubernetes sets none, requiring the runtime to be able to push arbitrary data to the Kata agent. As a result, on bare-metal Contrast deployments (AKS deployments are not affected) that run an image declaring at least one VOLUME for which no Kubernetes mount exists at that path, the untrusted host can write arbitrary file trees below that mount point inside the confidential container, compromising the integrity of a directory that is typically important to the application's core functionality. Version 1.9.1 fixes the issue by disallowing this configuration in contrast generate.

Affected Software

1 affected component
Edgeless Systems Contrast<=1.9.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Edgeless Systems Contrast to a version that resolves this vulnerability.

    Fixed in 1.9.1

Event History

Sep 27, 2026
CVE Published
via MITRE·01:28 AM
Data Sourced
via MITRE·01:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness
Feb 6, 58708
Event
via NVD·10:07 AM

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Bare-metal Contrast deployments running versions through 1.9.0 are affected when an image declares at least one VOLUME path that has no corresponding Kubernetes mount. AKS deployments are not affected.

2

What does an attacker need to exploit it?

The untrusted host must be able to act against a confidential container meeting the affected image and mount configuration. Exploitation relies on an image-declared VOLUME for which Kubernetes does not provide a mount at the same path.

3

What can the attacker do in an affected deployment?

The untrusted host can write arbitrary file trees beneath the affected mount point inside the confidential container. This compromises the integrity of a directory that is typically important to the application's core functionality.

4

How can I determine whether a workload is affected?

Check whether Contrast is version 1.9.0 or earlier on bare metal, then inspect the image OCI configuration or Dockerfile for VOLUME declarations. A workload is affected when Kubernetes does not define a mount at one or more of those declared paths.

5

What remediation is available?

Upgrade to Contrast 1.9.1. This version causes contrast generate to reject the unsafe configuration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203