PT-2026-109325 · Unknown · Privasys Go

CVE-2026-108267

·

Published

2026-10-09

·

Updated

2026-10-10

CVSS v4.0

9.1

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Privasys Go versions prior to 0.5.1-go1.26.5
Description In the challenge-mode RA-TLS (Remote Attestation TLS) implementation within crypto/tls, the software fails to bind the ReportData of the attestation quote to the active TLS session, binding it only to the certificate public key and client nonce. This allows an attacker possessing an enclave TLS private key to relay a genuine quote to a different connection. Consequently, a relying party may incorrectly accept a handshake terminated by the attacker as a verified attested enclave connection.
Recommendations Update to version 0.5.1-go1.26.5.

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-108267

Affected Products

Privasys Go