OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2025-71423

HIGH · CVSS 7.3 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Kubernetes versions 1.9.0 through 1.12.2 are vulnerable due to the Edgelesssys Contrast initializer logging the full NewMeshCert response, which includes sensitive workload secrets, to standard output at the INFO level. This exposure allows any Kubernetes user with permissions to access pod logs to view these secrets, potentially compromising encrypted storage and Vault integrations. Organizations using affected Kubernetes versions should prioritize remediation to protect sensitive data and maintain security integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-71423
Severity
HIGH
CVSS
7.3
EPSS
0.21%
Kubernetes

Original NVD Description

Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list permission on pods/logs. Because workload secrets are used for encrypted storage and Vault integration, those must also be considered compromised. This is a regression of GHSA-h5f8-crrq-4pw8.