CVE-2025-71426
Last modified
CVE-2025-71426 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party.
Description
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifest passes validation but whose secret seed is attacker-controlled. If network traffic is redirected from the legitimate Coordinator to the attacker's Coordinator, a workload owner can be impersonated when they either set a new manifest without comparing the returned root CA certificate against the existing one (the default behavior of the contrast CLI) or verify the Coordinator without comparing the root CA certificate against a trusted reference. Under these conditions the attacker can issue certificates that chain back to the rogue Coordinator's root CA and recover arbitrary workload secrets of workloads deployed after the attack. Secrets of the legitimate Coordinator (seed, workload secrets, CA), workload integrity, and certificates chaining to the mesh CA are not affected.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| edgelesssys | contrast | < 1.4.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2025-71426?
How severe is CVE-2025-71426?
How do I fix CVE-2025-71426?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-71420UVdesk core-framework before 1.1.7 contains an authorization…4.3
- CVE-2025-71421UVdesk core-framework before 1.1.7 contains an improper priv…7.2
- CVE-2025-71422Contrast is a Kubernetes runtime for confidential containers…5.7
- CVE-2025-71423Edgelesssys Contrast is a confidential-computing runtime for…7.3
- CVE-2025-71424Contrast, Edgeless Systems' runtime for confidential contain…3.5
- CVE-2025-71425Contrast (Edgeless Systems) before 1.8.1 logs the workload s…7.3
- CVE-2025-7143A vulnerability, which was classified as problematic, was fo…5.4
- CVE-2025-7144A vulnerability has been found in SourceCodester Best Salon …4.8
- CVE-2025-7145ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Co…8.6
- CVE-2025-7146The iPublish System developed by Jhenggao has an Arbitrary F…8.7
- CVE-2025-7147A vulnerability has been found in CodeAstro Patient Record M…9.8
- CVE-2025-7148A vulnerability was found in CodeAstro Simple Hospital Manag…5.4
Are you affected by CVE-2025-71426?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
