CVE-2025-71425

LOWCVSS 8.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affected. This exposes workload secrets — normally accessible only to the Contrast Coordinator, the initializer, the seedshare owner, and the workload owner — to Kubernetes users with get or list permission on pods/logs and to anyone with read access to the Kubernetes log storage, such as the cloud provider. Deployments that do not use workload secrets are unaffected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-29: 209-29
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Mohi@disismohi

    Your confidential computing runtime just logged the secret to Kubernetes. CVE-2025-71425 in Contrast (Edgeless Systems). Here's what to check this Tuesday.

    1000023
    81 followersView on X
  • Mohi@disismohi

    Secrets in logs is the most common confidentiality break in K8s. It happens in init containers, debug modes, and 'temporary' verbose logging that never got turned off. Default to warn. Audit what goes to stderr. source: https://nvd.nist.gov/vuln/detail/CVE-2025-71425

    000008
    81 followersView on X

Explore more