Database/Container, Kubernetes & orchestration
Contrast initializer: regression re-exposes workload secrets by logging the full NewMeshCert response
Impact
In Contrast 1.9.0 through 1.12.2 the initializer logs the entire NewMeshCert response at INFO, and that response carries the workload secret - a regression of the earlier fix tracked as GHSA-h5f8-crrq-4pw8 (see the related entry for CVE-2025-71425). Any Kubernetes user with get or list on pods/log reads the secret straight out of the log stream, and because workload secrets are used for encrypted storage and Vault integration, everything derived from them must be considered compromised too. Kept separate from the earlier issue because the affected version range and the logging site differ: an operator who patched once still needs to check whether they landed in the reintroduced window.
Who can reach it
Any authenticated Kubernetes principal with get or list on pods/log for the namespace running the initializer, plus anyone able to read the cluster's shipped logs. Requires low privilege, no exploitation.
What to do
Upgrade to Contrast 1.12.2 or later and redeploy the workloads so the initializer stops emitting the secret. Then rotate every workload secret exposed while an affected version ran, re-key encrypted storage and the Vault integration behind it, and purge the pod logs and downstream log copies that captured it. Workload redeploy plus secret rotation; no node drain or reboot.
References
Related entries
- Contrast initializer: workload secrets logged to Kubernetes pod logs at the default log levelCVE-2025-71425 · Contrast initializer (workload secret written to stderr at default log level)High
- LXD: crafted image templates escape the instance template directory and read or create host filesCVE-2026-16033 · LXD (image metadata template handling, QEMU/VM driver paths)High
- RHACM cluster-proxy: caller-supplied impersonation headers grant cluster-admin on managed clustersCVE-2026-17107 · Red Hat ACM / multicluster-engine cluster-proxy (service-proxy impersonation headers)High
- Argo Workflows (workflow executor, artifact driver logging): The executor logs the whole artifact driver struct, so S3CVE-2026-42295 · Argo Workflows (workflow executor, artifact driver logging)High
- Argo Workflows (Argo Server, ConfigMap-backed sync limit provider): The Sync Service's ConfigMap provider runs noCVE-2026-42297 · Argo Workflows (Argo Server, ConfigMap-backed sync limit provider)High
- KubeVela: a ComponentDefinition can point terraform.path at a symlink and OOM-kill the cluster-wide controllerCVE-2026-55108 · KubeVela vela-core controller (Terraform remote configuration loader, GetTerraformConfigurationFromRemote)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.