CVE-2026-108267None▾ SunlitPrivasys Go is a maintained fork of the Go programming language that adds RA-TLS support to crypto/tls. Prior to privasys-v0.5.1-go1.26.5, challenge-mode RA-TLS certificates bound quote ReportData to the certificate public key and client…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Privasys Go is a maintained fork of the Go programming language that adds RA-TLS support to crypto/tls. Prior to privasys-v0.5.1-go1.26.5, challenge-mode RA-TLS certificates bound quote ReportData to the certificate public key and client nonce but not to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept a handshake terminated by the attacker as an attested enclave connection. This issue is fixed in privasys-v0.5.1-go1.26.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-108268NoneEnclave OS Virtual runs container workloads inside confidential virtual machines with end-to-end attestation
CVE-2026-108269NoneRemote Attestation TLS Clients provides multi-language utilities for verifying attested TLS connections
CVE-2026-108266NonePrivasys rustls is a maintained fork of the rustls TLS library that adds RA-TLS challenge and channel-binding support
CVE-2026-108265NoneEnclave OS Mini is a Rust-based runtime for confidential applications inside Intel SGX enclaves
CVE-2026-108261Critical· 9.3Tina is a headless content management system
CVE-2026-107804Medium· 5.3Nginx UI is a web user interface for the Nginx web server