PT-2026-99444 · Edgelesssys · Contrast

·

CVE-2025-71423

·

Published

2025-08-28

·

Updated

2026-09-28

CVSS v4.0

8.5

High

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Edgelesssys Contrast versions 1.9.0 through 1.12.1
Description The initializer logs the full NewMeshCert response to standard output at the INFO level. This response contains the workload secret, making it accessible to any Kubernetes user with permissions to get or list pod logs. Since these workload secrets are utilized for Vault integration and encrypted storage, these components are also considered compromised.
Recommendations Update Edgelesssys Contrast to version 1.12.2 or later.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71423
GHSA-VXG3-W9RV-RHR2
GO-2025-3920

Affected Products

Contrast