CVE-2026-108265None▾ SunlitEnclave OS Mini is a Rust-based runtime for confidential applications inside Intel SGX enclaves. Prior to wasm-v0.40.0, the SGX runtime's RA-TLS challenge certificate path placed the certificate public-key hash and client nonce in quote …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Enclave OS Mini is a Rust-based runtime for confidential applications inside Intel SGX enclaves. Prior to wasm-v0.40.0, the SGX runtime's RA-TLS challenge certificate path placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept an attacker-terminated connection as the attested enclave. This issue is fixed in wasm-v0.40.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-108266NonePrivasys rustls is a maintained fork of the rustls TLS library that adds RA-TLS challenge and channel-binding support
CVE-2026-108261Critical· 9.3Tina is a headless content management system
CVE-2026-107804Medium· 5.3Nginx UI is a web user interface for the Nginx web server
CVE-2025-59845High· 8.2Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL
CVE-2026-61435High· 8.2PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
CVE-2026-107295High· 7.6Pydantic AI is a Python agent framework for building applications and workflows with Generative AI