Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 27 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Edgelesssys
Edgelesssys contrast |
|
| Vendors & Products |
Edgelesssys
Edgelesssys contrast |
Sun, 27 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list permission on pods/logs. Because workload secrets are used for encrypted storage and Vault integration, those must also be considered compromised. This is a regression of GHSA-h5f8-crrq-4pw8. | |
| Title | Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure | |
| Weaknesses | CWE-532 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-27T01:28:25.878Z
Reserved: 2026-09-27T00:18:19.534Z
Link: CVE-2025-71423
No data.
Status : Received
Published: 2026-09-27T02:17:15.993
Modified: 2026-09-27T02:17:15.993
Link: CVE-2025-71423
No data.
OpenCVE Enrichment
Updated: 2026-09-27T11:43:08Z
-
CWE-532
Insertion of Sensitive Information into Log File