PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-71423 edgelesssys CVE debrief

A confidential-computing runtime for Kubernetes, Edgelesssys Contrast, exposed workload secrets in its initializer logs before version 1.12.2. This issue allows any Kubernetes user with get or list permission on pods/logs to access these secrets, potentially compromising encrypted storage and Vault integration. The vulnerability was introduced in version 1.9.0 and patched in version 1.12.2. Defenders should prioritize upgrading and reviewing access controls. The CVE record and source item provide details on the vulnerability, including the affected versions and patch commits.

Vendor
edgelesssys
Product
contrast
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-27
Original CVE updated
2026-10-08
Advisory published
2026-09-27
Advisory updated
2026-10-08

Who should care

Kubernetes administrators and users with get or list permission on pods/logs should assess exposure and prioritize upgrading to version 1.12.2 or later. Operators, platform teams, and security teams need to review access controls and ensure that only authorized users have access to pods/logs. Vulnerability management and security teams should track exceptions and verify evidence of remediation.

Why it matters

CVE-2025-71423 allows unauthorized access to workload secrets in Edgelesssys Contrast before version 1.12.2, potentially compromising encrypted storage and Vault integration. Defenders should prioritize upgrading and reviewing access controls.

  • Secrets exposure requires immediate attention to prevent potential misuse
  • Encrypted storage and Vault integration may be compromised
  • Access controls for pods/logs need review and restriction

Technical summary

Edgelesssys Contrast, a confidential-computing runtime for Kubernetes, logged workload secrets in its initializer logs at INFO level in versions 1.9.0 before 1.12.2. This allows any Kubernetes user with get or list permission on pods/logs to access these secrets, potentially compromising encrypted storage and Vault integration. The vulnerability was patched in version 1.12.2. Defenders should prioritize upgrading and reviewing access controls for pods/logs. The fix involves removing sensitive information from logs.

Defensive priority

Defenders should prioritize upgrading to version 1.12.2 or later and review access controls for pods/logs.

Recommended defensive actions

  • Upgrade to Edgelesssys Contrast version 1.12.2 or later
  • Review and restrict access controls for pods/logs
  • Monitor for potential misuse of exposed workload secrets
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability, including the affected versions (1.9.0 to 1.12.1) and patch commits. Vendor advisory GHSA-vxg3-w9rv-rhr2 and patch commit information are available. Defenders should verify affected scope and review official guidance for mitigation steps. The vulnerability allows unauthorized access to workload secrets, potentially compromising encrypted storage and Vault integration.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-71423 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-71423

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-71423 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-71423

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/71xxx/CVE-2025-71423.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/edgelesssys/contrast/security/advisories/GHSA-vxg3-w9rv-rhr2

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/edgelesssys/contrast/commit/5a5512c4af63c17bb66331e7bd2768a863b2f225

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/edgelesssys/contrast/commit/cf58026b30c43fe7df91eac5322da02e1725d554

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/edgelesssys-contrast-before-1.12.2-workload-secrets-information-disclosure

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.