๐Ÿ” CVE Alert

CVE-2025-71426

HIGH 7.1

Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifest passes validation but whose secret seed is attacker-controlled. If network traffic is redirected from the legitimate Coordinator to the attacker's Coordinator, a workload owner can be impersonated when they either set a new manifest without comparing the returned root CA certificate against the existing one (the default behavior of the contrast CLI) or verify the Coordinator without comparing the root CA certificate against a trusted reference. Under these conditions the attacker can issue certificates that chain back to the rogue Coordinator's root CA and recover arbitrary workload secrets of workloads deployed after the attack. Secrets of the legitimate Coordinator (seed, workload secrets, CA), workload integrity, and certificates chaining to the mesh CA are not affected.

CWE CWE-285
Vendor edgelesssys
Product contrast
Published Sep 27, 2026
Stay Ahead of the Next One

Get instant alerts for edgelesssys contrast

Be the first to know when new high vulnerabilities affecting edgelesssys contrast are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

edgelesssys / contrast
0 < 1.4.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/edgelesssys/contrast/security/advisories/GHSA-vqv5-385r-2hf8 vulncheck.com: https://www.vulncheck.com/advisories/contrast-before-1.4.1-coordinator-impersonation-via-unauthenticated-recovery

Credits

3u13r burgerdev katexochen