CVE-2025-71423
Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response โ which contains the workload secret โ to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list permission on pods/logs. Because workload secrets are used for encrypted storage and Vault integration, those must also be considered compromised. This is a regression of GHSA-h5f8-crrq-4pw8.
| CWE | CWE-532 |
| Vendor | edgelesssys |
| Product | contrast |
| Published | Sep 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for edgelesssys contrast
Be the first to know when new high vulnerabilities affecting edgelesssys contrast are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
edgelesssys / contrast
1.9.0 < 1.12.2
References
github.com: https://github.com/edgelesssys/contrast/security/advisories/GHSA-vxg3-w9rv-rhr2 github.com: https://github.com/edgelesssys/contrast/commit/5a5512c4af63c17bb66331e7bd2768a863b2f225 github.com: https://github.com/edgelesssys/contrast/commit/cf58026b30c43fe7df91eac5322da02e1725d554 vulncheck.com: https://www.vulncheck.com/advisories/edgelesssys-contrast-before-1.12.2-workload-secrets-information-disclosure
Credits
katexochen