CVE-2025-71423 Overview
CVE-2025-71423 is an information disclosure vulnerability in Edgelesssys Contrast, a confidential-computing runtime for Kubernetes. In versions 1.9.0 through 1.12.1, the initializer logs the full NewMeshCert response at INFO level. This response contains the workload secret used for encrypted storage and Vault integration. Any Kubernetes user holding get or list permissions on pods/logs can read these secrets directly from standard output. The issue is a regression of a previously patched flaw tracked as GHSA-h5f8-crrq-4pw8. It is classified under CWE-532: Insertion of Sensitive Information into Log File.
Critical Impact
Workload secrets exposed through pod logs must be treated as fully compromised, including any encrypted storage keys and Vault integration material derived from them.
Affected Products
- Edgelesssys Contrast versions 1.9.0 through 1.12.1
- Contrast initializer component (initializer/main.go)
- Confidential-computing workloads using Contrast on Kubernetes
Discovery Timeline
- 2026-09-27 - CVE-2025-71423 published to NVD
- 2026-09-28 - Last updated in NVD database
Technical Details for CVE-2025-71423
Vulnerability Analysis
Contrast's initializer requests a mesh certificate from the Coordinator service during workload startup. The response from NewMeshCert contains both certificate material and a workload secret used to derive storage encryption keys and authenticate with HashiCorp Vault. The initializer wrote the entire response structure into its log stream at INFO level. Kubernetes aggregates container stdout into pod logs accessible through the API server. Any principal granted the pods/logs subresource verb on the initializer's namespace can retrieve the secret with a single kubectl logs call. The exposure persists for as long as the log entries remain available through the kubelet, log forwarders, or any downstream log aggregation system.
Root Cause
The root cause is unsanitized logging of a sensitive response structure. The log.Info call passed the full resp object as a structured field without filtering credential material. This violates the principle that secrets must never cross a logging boundary. The regression indicates the earlier fix for GHSA-h5f8-crrq-4pw8 was not covered by a regression test that would have caught the reintroduction.
Attack Vector
Exploitation requires access to the Kubernetes API with permission to read pod logs in the namespace running Contrast workloads. An authenticated low-privilege user, a compromised service account, or any log aggregation pipeline forwarding stdout can retrieve the plaintext workload secret. Because the secret bootstraps encrypted storage and Vault authentication, recovery requires rotating both.
// Patch from initializer/main.go — remove sensitive response from logs
for {
resp, err = requestCert()
if err == nil {
- log.Info("Requesting cert", "response", resp)
+ log.Info("Successfully requested cert from Coordinator")
break
}
log.Warn("Requesting cert", "err", err)
}
Source: GitHub Commit 5a5512c
Detection Methods for CVE-2025-71423
Indicators of Compromise
- Log lines containing the string Requesting cert with a response structured field present in Contrast initializer pod logs.
- Historical pod logs or log aggregation indices retaining NewMeshCert response payloads from Contrast versions 1.9.0 through 1.12.1.
- Unexpected get or list activity against pods/logs resources in namespaces running Contrast workloads.
Detection Strategies
- Query Kubernetes audit logs for API calls to the pods/log subresource targeting namespaces that host Contrast initializers.
- Scan existing log stores and SIEM indices for the vulnerable log pattern to identify where secrets may have been exfiltrated or retained.
- Inventory Contrast deployments and compare running image versions against the fixed version 1.12.2.
Monitoring Recommendations
- Alert on any service account or user outside the expected administrative set reading initializer pod logs.
- Enable retention and review of Kubernetes audit logs at the Metadata level or higher for pods/logs access.
- Monitor Vault audit logs for authentication attempts using workload identities that may have been exposed.
How to Mitigate CVE-2025-71423
Immediate Actions Required
- Upgrade Edgelesssys Contrast to version 1.12.2 or later across all clusters running affected versions.
- Rotate all workload secrets, including derived storage encryption keys and Vault credentials associated with Contrast workloads.
- Purge archived pod logs and log aggregation records containing the NewMeshCert response payload.
- Review and tighten RBAC bindings granting the pods/logs subresource verb in affected namespaces.
Patch Information
The fix removes the sensitive response from the structured log entry. Review the upstream commits 5a5512c and cf58026b, along with the GitHub Security Advisory GHSA-vxg3-w9rv-rhr2 and the VulnCheck Advisory.
Workarounds
- If immediate upgrade is not possible, restrict the pods/logs subresource through RBAC to a minimal set of cluster administrators.
- Disable or filter log forwarding from Contrast initializer containers until the upgrade is applied.
- Treat any environment that ran versions 1.9.0 through 1.12.1 as having compromised workload secrets and plan rotation accordingly.
# Restrict read access to pod logs in namespaces running Contrast workloads
kubectl create role contrast-logs-readonly \
--verb=get,list \
--resource=pods/log \
--namespace=contrast-system
# Bind only to explicit administrators
kubectl create rolebinding contrast-logs-readonly-binding \
--role=contrast-logs-readonly \
--user=cluster-admin@example.com \
--namespace=contrast-system
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.