PT-2026-99446 · Edgeless Systems · Contrast

·

CVE-2025-71425

·

Published

2025-05-28

·

Updated

2026-09-29

CVSS v4.0

8.5

High

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Contrast (Edgeless Systems) versions prior to 1.8.1
Description The Contrast initializer logs the workload secret to stderr, which directs the information into Kubernetes logs. This occurs when the CONTRAST LOG LEVEL variable is set to info or debug. Since info is the default setting, most installations are affected. This issue exposes workload secrets to Kubernetes users with permissions to get or list pods/logs, as well as entities with read access to the Kubernetes log storage, such as cloud providers.
Recommendations Update Contrast (Edgeless Systems) to version 1.8.1 or later. As a temporary mitigation, change the CONTRAST LOG LEVEL variable to a level other than info or debug.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71425
GHSA-H5F8-CRRQ-4PW8
GO-2025-3718

Affected Products

Contrast