CVE-2025-71423
7.3 HIGHpublic exploit availablePublished 2026-09-27 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list permission on pods/logs. Because workload secrets are used for encrypted storage and Vault integration, those must also be considered compromised. This is a regression of GHSA-h5f8-crrq-4pw8.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-532
Public exploit & PoC references
All references
- https://github.com/edgelesssys/contrast/commit/5a5512c4af63c17bb66331e7bd2768a863b2f225
- https://github.com/edgelesssys/contrast/commit/cf58026b30c43fe7df91eac5322da02e1725d554
- https://github.com/edgelesssys/contrast/security/advisories/GHSA-vxg3-w9rv-rhr2
- https://www.vulncheck.com/advisories/edgelesssys-contrast-before-1.12.2-workload-secrets-information-disclosure
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2025-71425PoC
- UNSCOREDCVE-2026-14442
- UNSCOREDCVE-2026-14443
- HIGHCVE-2026-49810
- UNSCOREDCVE-2026-63208PoC
- UNSCOREDCVE-2026-66068PoC
- UNSCOREDCVE-2026-77285PoC
- UNSCOREDCVE-2026-82371
Related by shared AI tags and CWE weakness class. Browse the full archive.