Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-108265— enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session

Quick assessment

Affected
Privasys enclave-os-mini
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Enclave OS Mini 是基于 Rust 的运行时环境,用于在 Intel SGX 飞地(enclave)中运行机密应用。在 wasm-v0.40.0 版本之前,SGX 运行时的远程认证(RA-TLS)挑战证书路径将证书的公钥哈希和客户端非ces数(nonce)放入 Quote 的 ReportData 字段中,但遗漏了与当前 TLS 会话绑定的特定值。攻击者若能获取飞地的 TLS 私钥,便可将有效的 Quote 中继到另一个连接上,导致依赖方(relying party)错误地将由攻击者终止的连接识别为经

CVSS 9.1 · Critical

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-108265

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session
Source: CVE Program / CVE List V5
Vulnerability Description
Enclave OS Mini is a Rust-based runtime for confidential applications inside Intel SGX enclaves. Prior to wasm-v0.40.0, the SGX runtime's RA-TLS challenge certificate path placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept an attacker-terminated connection as the attested enclave. This issue is fixed in wasm-v0.40.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
源验证错误
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Privasys enclave-os-mini < wasm-v0.40.0 -

II. Public POCs for CVE-2026-108265

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-108265

请登录查看更多情报信息。

Other References for CVE-2026-108265 (4)

Same Patch Batch · Privasys · 2026-10-09 · 5 CVEs total

CVE-2026-108266 9.1 CRITICAL Privasys rustls fork: RA-TLS challenge mode did not bind attestation evidence to the TLS s
CVE-2026-108269 9.1 CRITICAL ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session
CVE-2026-108267 9.1 CRITICAL Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS sessi
CVE-2026-108268 9.1 CRITICAL enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session

IV. Related Vulnerabilities

V. Comments for CVE-2026-108265

No comments yet


Leave a comment