---
id: CVE-2026-108269
title: >-
  Remote Attestation TLS Clients provides multi-language utilities for verifying
  attested TLS connections
summary: >-
  Remote Attestation TLS Clients provides multi-language utilities for verifying
  attested TLS connections. Prior to 0.5.0, the Rust and Go RA-TLS challenge
  verifiers accepted quote ReportData that was bound to the certificate public
  key an…
severity: none
cwe:
  - CWE-346
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T22:16:59.793'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108269'
references:
  - url: >-
      https://github.com/Privasys/ra-tls-clients/commit/b8de9bcadd0f81ca8882d15095fc0d9c50e40148
    label: security-advisories@github.com
  - url: 'https://github.com/Privasys/ra-tls-clients/releases/tag/v0.5.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx
    label: security-advisories@github.com
  - url: >-
      https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx
    label: security-advisories@github.com
  - url: 'https://privasys.org/blog/binding-attestation-to-the-tls-session'
    label: security-advisories@github.com
tags:
  - nvd
ingestedAt: '2026-10-09T23:16:19.788Z'
---

## Overview

Remote Attestation TLS Clients provides multi-language utilities for verifying attested TLS connections. Prior to 0.5.0, the Rust and Go RA-TLS challenge verifiers accepted quote ReportData that was bound to the certificate public key and client nonce but not to the active TLS session before permitting application traffic. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing the clients to accept an attacker-terminated connection as the attested enclave. This issue is fixed in 0.5.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
