PatchSiren cyber security CVE debrief
CVE-2025-71423 edgelesssys CVE debrief
A confidential-computing runtime for Kubernetes, Edgelesssys Contrast, exposed workload secrets in its initializer logs before version 1.12.2. This issue allows any Kubernetes user with get or list permission on pods/logs to access these secrets, potentially compromising encrypted storage and Vault integration. The vulnerability was introduced in version 1.9.0 and patched in version 1.12.2. Defenders should prioritize upgrading and reviewing access controls. The CVE record and source item provide details on the vulnerability, including the affected versions and patch commits.
- Vendor
- edgelesssys
- Product
- contrast
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-27
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-09-27
- Advisory updated
- 2026-10-08
Who should care
Kubernetes administrators and users with get or list permission on pods/logs should assess exposure and prioritize upgrading to version 1.12.2 or later. Operators, platform teams, and security teams need to review access controls and ensure that only authorized users have access to pods/logs. Vulnerability management and security teams should track exceptions and verify evidence of remediation.
Why it matters
CVE-2025-71423 allows unauthorized access to workload secrets in Edgelesssys Contrast before version 1.12.2, potentially compromising encrypted storage and Vault integration. Defenders should prioritize upgrading and reviewing access controls.
- Secrets exposure requires immediate attention to prevent potential misuse
- Encrypted storage and Vault integration may be compromised
- Access controls for pods/logs need review and restriction
Technical summary
Edgelesssys Contrast, a confidential-computing runtime for Kubernetes, logged workload secrets in its initializer logs at INFO level in versions 1.9.0 before 1.12.2. This allows any Kubernetes user with get or list permission on pods/logs to access these secrets, potentially compromising encrypted storage and Vault integration. The vulnerability was patched in version 1.12.2. Defenders should prioritize upgrading and reviewing access controls for pods/logs. The fix involves removing sensitive information from logs.
Defensive priority
Defenders should prioritize upgrading to version 1.12.2 or later and review access controls for pods/logs.
Recommended defensive actions
- Upgrade to Edgelesssys Contrast version 1.12.2 or later
- Review and restrict access controls for pods/logs
- Monitor for potential misuse of exposed workload secrets
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, including the affected versions (1.9.0 to 1.12.1) and patch commits. Vendor advisory GHSA-vxg3-w9rv-rhr2 and patch commit information are available. Defenders should verify affected scope and review official guidance for mitigation steps. The vulnerability allows unauthorized access to workload secrets, potentially compromising encrypted storage and Vault integration.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-71423 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-71423
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-71423 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-71423
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/71xxx/CVE-2025-71423.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/edgelesssys/contrast/security/advisories/GHSA-vxg3-w9rv-rhr2
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/edgelesssys/contrast/commit/5a5512c4af63c17bb66331e7bd2768a863b2f225
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/edgelesssys/contrast/commit/cf58026b30c43fe7df91eac5322da02e1725d554
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/edgelesssys-contrast-before-1.12.2-workload-secrets-information-disclosure
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.