Information Disclosure Vulnerability in Contrast by Edgeless Systems
CVE-2025-71425

8.5HIGH

Key Information:

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2025-71425?

The Contrast product prior to version 1.8.1 has a vulnerability where workload secrets are logged to stderr when the Contrast initializer is set to log levels of info or debug. This poses a significant risk as it allows unauthorized Kubernetes users with permission to access pod logs to view sensitive information typically restricted to specific roles. Administrators who do not adjust the default log level settings may inadvertently expose these secrets, leading to potential breaches and unauthorized access to critical workload data.

Affected Version(s)

contrast 0 < 1.8.1

contrast 1.8.1

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

burgerdev
katexochen
thomasten
.