---
id: CVE-2026-92702
title: >-
  Cocos AI is a confidential computing system for running AI workloads inside
  trusted execution environments
summary: >-
  Cocos AI is a confidential computing system for running AI workloads inside
  trusted execution environments. In versions up to and including 0.8.2, the
  intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not
  enforce att…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-346
vendor: ultravioletrs
product: cocos
affected:
  - cocos < 0.9.0
published: '2026-09-18'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:25:27.050'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92702'
references:
  - url: >-
      https://github.com/ultravioletrs/cocos/commit/80bf813c48300f02259b338b91f844c71be582ea
    label: security-advisories@github.com
  - url: 'https://github.com/ultravioletrs/cocos/pull/582'
    label: security-advisories@github.com
  - url: 'https://github.com/ultravioletrs/cocos/releases/tag/v0.9.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw
    label: security-advisories@github.com
  - url: >-
      https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00308
epssPercentile: 0.20984
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-22T15:05:11.173074Z'
ingestedAt: '2026-09-18T17:46:41.553Z'
---

## Overview

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation freshness when the expected reportData value is nil, empty, or omitted, leaving the SEV-SNP policy ReportData unset so the verifier accepts unrelated or stale Evidence not bound to the current connection. A relying party that uses this path without an expected reportData as a trust or authorization decision can be induced to trust an unintended attestation context; a supplied non-empty reportData is still validated. The issue is fixed in version 0.9.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
