Database/Container, Kubernetes & orchestration
Contrast initializer: workload secrets logged to Kubernetes pod logs at the default log level
Impact
The Contrast initializer writes the workload secret to stderr, which Kubernetes captures as pod logs. Because info is the default log level, installations that never touched CONTRAST_LOG_LEVEL are affected. Workload secrets back encrypted storage and Vault integration, so anyone with get or list on pods/log - a broad, commonly granted RBAC verb - or read access to wherever the cluster ships its logs, including the cloud provider, obtains material that decrypts tenant data. On a multi-tenant GPU cluster that means a namespace-scoped tenant or an observability pipeline can read secrets the confidential-computing design intended to keep from the platform operator entirely. The record notes this issue recurred later as CVE-2025-71423 in the 1.9.0-1.12.2 range; deployments that do not use workload secrets are unaffected.
Who can reach it
Any authenticated Kubernetes principal with get or list on pods/log in the workload namespace, or anyone with read access to the cluster's log storage or the cloud provider's logging backend. No exploit, only a log read.
What to do
Upgrade Contrast to 1.8.1 or later and redeploy affected workloads so the initializer runs the fixed code. Treat every workload secret that was ever logged as compromised: rotate the secrets, re-key anything encrypted under them, rotate the Vault material they unlocked, and purge or restrict the retained pod logs and any log-aggregation copies. Rotation, not the upgrade, is the expensive part. Cost is a workload redeploy plus credential rotation; no node maintenance.
References
Related entries
- LXD: crafted image templates escape the instance template directory and read or create host filesCVE-2026-16033 · LXD (image metadata template handling, QEMU/VM driver paths)High
- RHACM cluster-proxy: caller-supplied impersonation headers grant cluster-admin on managed clustersCVE-2026-17107 · Red Hat ACM / multicluster-engine cluster-proxy (service-proxy impersonation headers)High
- Argo Workflows (workflow executor, artifact driver logging): The executor logs the whole artifact driver struct, so S3CVE-2026-42295 · Argo Workflows (workflow executor, artifact driver logging)High
- Argo Workflows (Argo Server, ConfigMap-backed sync limit provider): The Sync Service's ConfigMap provider runs noCVE-2026-42297 · Argo Workflows (Argo Server, ConfigMap-backed sync limit provider)High
- KubeVela: a ComponentDefinition can point terraform.path at a symlink and OOM-kill the cluster-wide controllerCVE-2026-55108 · KubeVela vela-core controller (Terraform remote configuration loader, GetTerraformConfigurationFromRemote)High
- CloudNativePG: managed-role passwords exposed via pg_stat_statements, enabling command execution in the DB podCVE-2026-55765 · CloudNativePG operator (managed-role password handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.