
Your confidential computing runtime just logged the secret to Kubernetes. CVE-2025-71425 in Contrast (Edgeless Systems). Here's what to check this Tuesday.
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affected. This exposes workload secrets — normally accessible only to the Contrast Coordinator, the initializer, the seedshare owner, and the workload owner — to Kubernetes users with get or list permission on pods/logs and to anyone with read access to the Kubernetes log storage, such as the cloud provider. Deployments that do not use workload secrets are unaffected.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

Your confidential computing runtime just logged the secret to Kubernetes. CVE-2025-71425 in Contrast (Edgeless Systems). Here's what to check this Tuesday.

Secrets in logs is the most common confidentiality break in K8s. It happens in init containers, debug modes, and 'temporary' verbose logging that never got turned off. Default to warn. Audit what goes to stderr. source: https://nvd.nist.gov/vuln/detail/CVE-2025-71425