CVE-2026-108268None▾ SunlitEnclave OS Virtual runs container workloads inside confidential virtual machines with end-to-end attestation. Prior to tdx-v0.2.43 and tdx-gpu-v0.6.27, the TDX/GPU RA-TLS certificate issuer placed the certificate public-key hash and clie…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Enclave OS Virtual runs container workloads inside confidential virtual machines with end-to-end attestation. Prior to tdx-v0.2.43 and tdx-gpu-v0.6.27, the TDX/GPU RA-TLS certificate issuer placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept an attacker-terminated connection as the attested enclave. This issue is fixed in tdx-v0.2.43 and tdx-gpu-v0.6.27.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-108269NoneRemote Attestation TLS Clients provides multi-language utilities for verifying attested TLS connections
CVE-2026-108267NonePrivasys Go is a maintained fork of the Go programming language that adds RA-TLS support to crypto/tls
CVE-2026-108266NonePrivasys rustls is a maintained fork of the rustls TLS library that adds RA-TLS challenge and channel-binding support
CVE-2026-108265NoneEnclave OS Mini is a Rust-based runtime for confidential applications inside Intel SGX enclaves
CVE-2026-108261Critical· 9.3Tina is a headless content management system
CVE-2026-107804Medium· 5.3Nginx UI is a web user interface for the Nginx web server