CVE-2026-108269: The RA-TLS challenge verifier in ra-tls-clients accepted quote ReportData bound to the certificate public key and client nonce but not to the active TLS session. This allowed an attacker with an enclave TLS private key to relay a genuine quote onto another connection, causing clients to accept an attacker-terminated connection as attested. The issue is fixed in version 0.5.0. Defenders sh [truncated]
CVE-2026-108268 debrief: Enclave OS Virtual RA-TLS certificates were not bound to the TLS session, allowing potential relay attacks. This issue is fixed in tdx-v0.2.43 and tdx-gpu-v0.6.27. The vulnerability impacts confidentiality and integrity of attested connections. Defenders should assess exposure and prioritize updates to prevent exploitation. The issue involves TDX/GPU RA-TLS certificate issuer omit [truncated]
A critical vulnerability was found in Privasys Go, a maintained fork of the Go programming language, which adds RA-TLS support to crypto/tls. The issue is related to the RA-TLS challenge mode not binding attestation evidence to the TLS session. This could allow an attacker who obtained an enclave TLS private key to relay a genuine quote onto another connection, causing a relying party to accept a handshak [truncated]
A critical vulnerability was found in Privasys rustls fork, affecting RA-TLS challenge mode. The issue allowed an attacker to relay genuine quote attestation evidence onto another connection, potentially causing a relying party to accept an attacker-terminated connection as attested. This vulnerability is fixed in privasys-v0.8.1. The vulnerability impacts systems relying on RA-TLS challenge mode for atte [truncated]
A vulnerability in enclave-os-mini allows an attacker with an enclave TLS private key to relay a genuine quote onto another connection, causing a relying party to accept an attacker-terminated connection as the attested enclave. This issue is fixed in wasm-v0.40.0. The vulnerability impacts confidential applications inside Intel SGX enclaves using enclave-os-mini. Defenders should assess exposure and prio [truncated]