Contrast is a confidential-computing runtime for Kubernetes. (CVE-2025-71426)
CVE-2025-71426 affects Contrast, a confidential-computing runtime for Kubernetes, in versions before 1.4.1. The vulnerability allows an attacker to set up a rogue Coordinator whose manifest passes validation but uses an attacker-controlled secret seed. If network traffic is redirected to this rogue Coordinator, the attacker can impersonate workload owners and issue certificates that enable recovery of arbitrary workload secrets for workloads deployed after the attack. The legitimate Coordinator's secrets and certificates chaining to the mesh CA are not impacted.
AI Analysis
Technical Summary
Contrast versions before 1.4.1 have a vulnerability where a recovering Coordinator does not verify the seed supplied by the recovering party. This allows an attacker to deploy a rogue Coordinator with a valid manifest but attacker-controlled secret seed. If network traffic is redirected from the legitimate Coordinator to the rogue one, and the workload owner does not verify the root CA certificate against a trusted reference (default behavior of the contrast CLI), the attacker can impersonate the workload owner. This enables issuance of certificates chaining to the rogue Coordinator's root CA and recovery of arbitrary workload secrets for workloads deployed after the compromise. The legitimate Coordinator's secrets and mesh CA certificates remain secure.
Potential Impact
An attacker who can redirect network traffic to a rogue Coordinator can impersonate workload owners and recover arbitrary workload secrets for workloads deployed after the attack. This compromises confidentiality of those workload secrets. The integrity of workloads and certificates chaining to the legitimate mesh CA are not affected, nor are the legitimate Coordinator's secrets.
Mitigation Recommendations
No explicit patch or remediation is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Mitigation requires verifying the root CA certificate against a trusted reference when setting a new manifest or verifying the Coordinator, instead of relying on the default behavior of the contrast CLI.
Contrast is a confidential-computing runtime for Kubernetes. (CVE-2025-71426)
Description
CVE-2025-71426 affects Contrast, a confidential-computing runtime for Kubernetes, in versions before 1.4.1. The vulnerability allows an attacker to set up a rogue Coordinator whose manifest passes validation but uses an attacker-controlled secret seed. If network traffic is redirected to this rogue Coordinator, the attacker can impersonate workload owners and issue certificates that enable recovery of arbitrary workload secrets for workloads deployed after the attack. The legitimate Coordinator's secrets and certificates chaining to the mesh CA are not impacted.
CVSS v3.1
Score 7.1high
Affected software
pkg:github/edgelesssys/contrastRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Contrast versions before 1.4.1 have a vulnerability where a recovering Coordinator does not verify the seed supplied by the recovering party. This allows an attacker to deploy a rogue Coordinator with a valid manifest but attacker-controlled secret seed. If network traffic is redirected from the legitimate Coordinator to the rogue one, and the workload owner does not verify the root CA certificate against a trusted reference (default behavior of the contrast CLI), the attacker can impersonate the workload owner. This enables issuance of certificates chaining to the rogue Coordinator's root CA and recovery of arbitrary workload secrets for workloads deployed after the compromise. The legitimate Coordinator's secrets and mesh CA certificates remain secure.
Potential Impact
An attacker who can redirect network traffic to a rogue Coordinator can impersonate workload owners and recover arbitrary workload secrets for workloads deployed after the attack. This compromises confidentiality of those workload secrets. The integrity of workloads and certificates chaining to the legitimate mesh CA are not affected, nor are the legitimate Coordinator's secrets.
Mitigation Recommendations
No explicit patch or remediation is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Mitigation requires verifying the root CA certificate against a trusted reference when setting a new manifest or verifying the Coordinator, instead of relying on the default behavior of the contrast CLI.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-m5hp-85q9-x6vh
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-71426"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6ab89bc2f7a7c54106941ed2
Added to database: 09/27/2026, 04:29:54 UTC
Last enriched: 09/27/2026, 04:36:58 UTC
Last updated: 09/27/2026, 13:47:42 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.