๐Ÿ” CVE Alert

CVE-2025-71423

HIGH 7.3

Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response โ€” which contains the workload secret โ€” to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list permission on pods/logs. Because workload secrets are used for encrypted storage and Vault integration, those must also be considered compromised. This is a regression of GHSA-h5f8-crrq-4pw8.

CWE CWE-532
Vendor edgelesssys
Product contrast
Published Sep 27, 2026
Stay Ahead of the Next One

Get instant alerts for edgelesssys contrast

Be the first to know when new high vulnerabilities affecting edgelesssys contrast are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

edgelesssys / contrast
1.9.0 < 1.12.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/edgelesssys/contrast/security/advisories/GHSA-vxg3-w9rv-rhr2 github.com: https://github.com/edgelesssys/contrast/commit/5a5512c4af63c17bb66331e7bd2768a863b2f225 github.com: https://github.com/edgelesssys/contrast/commit/cf58026b30c43fe7df91eac5322da02e1725d554 vulncheck.com: https://www.vulncheck.com/advisories/edgelesssys-contrast-before-1.12.2-workload-secrets-information-disclosure

Credits

katexochen