{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/atls/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:contrast:contrast:*:*:*:*:*:kubernetes:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2025-71426"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Contrast (\u003c 1.4.1)","Contrast (\u003c 1.16.0)"],"_cs_severities":["high"],"_cs_tags":["kubernetes","confidential-computing","cve","vulnerability","attestation","aTLS","CVE-2026-100835"],"_cs_type":"advisory","_cs_vendors":["Contrast"],"content_html":"\u003cp\u003eContrast, a confidential-computing runtime for Kubernetes, contains a vulnerability (CVE-2025-71426) in versions prior to 1.4.1. The flaw resides in the recovery process of the Coordinator, which fails to verify the cryptographic seed provided by a recovering party. This oversight allows an attacker to deploy a rogue Coordinator that satisfies initial manifest validation requirements but utilizes an attacker-controlled secret seed. If the attacker succeeds in redirecting network traffic from the legitimate Coordinator to their rogue instance, they can successfully impersonate the Coordinator. This is particularly effective if the workload owner fails to manually verify the root CA certificate against a trusted reference, which is common given the default behavior of the contrast CLI. Once the rogue Coordinator is trusted, the attacker can issue certificates that chain to their own CA, enabling the recovery of secrets for any workloads deployed after the traffic redirection.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to Kubernetes workloads using Contrast for confidential computing. If exploited, an attacker can access sensitive workload secrets. While the legitimate Coordinator's internal secrets (such as its own seed and CA) remain secure, the exposure of workload-specific secrets impacts the confidentiality of data-in-use for services deployed within the compromised mesh.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Contrast Kubernetes runtime to version 1.4.1 or later to remediate CVE-2025-71426.\u003c/li\u003e\n\u003cli\u003eAudit Kubernetes network policies to restrict unauthorized traffic redirection to sensitive control plane components.\u003c/li\u003e\n\u003cli\u003eMandate strict verification of root CA certificates for all Coordinator communication, ensuring they are compared against known-good trusted references rather than relying on default CLI behavior.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-27T03:04:02Z","date_published":"2026-09-27T03:03:34Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-71426/","summary":"A vulnerability in the Contrast confidential-computing runtime allows attackers to impersonate a legitimate Coordinator by supplying a malicious seed during recovery, leading to the potential recovery of workload secrets.","title":"Improper Seed Verification in Contrast Kubernetes Confidential-Computing Runtime","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-71426/"}],"language":"en","title":"CraftedSignal Threat Feed - ATLS","version":"https://jsonfeed.org/version/1.1"}