Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-108269— ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session

Quick assessment

Affected
Privasys ra-tls-clients
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Remote Attestation TLS(RA-TLS)客户端提供了多种语言的实用工具,用于验证经过远程证明的 TLS 连接。在版本 0.5.0 之前,Rust 和 Go 语言的 RA-TLS 挑战验证器在接受.quote 报告数据(ReportData)时,仅将其与证书公钥和客户端非确定性值(nonce)绑定,而未将其与当前活跃的 TLS 会话绑定,便允许应用流量通过。如果攻击者获取了某个 enclave(可信执行环境)的 TLS 私钥,便可以将一个真实的证明(quote)中继到另一个连接上,从而导致客户端错

CVSS 9.1 · Critical EPSS 0.13% · P2

Affected Version Matrix 1

VendorProduct Version RangeStatus
Privasys ra-tls-clients < 0.5.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-108269

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session
Source: CVE Program / CVE List V5
Vulnerability Description
Remote Attestation TLS Clients provides multi-language utilities for verifying attested TLS connections. Prior to 0.5.0, the Rust and Go RA-TLS challenge verifiers accepted quote ReportData that was bound to the certificate public key and client nonce but not to the active TLS session before permitting application traffic. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing the clients to accept an attacker-terminated connection as the attested enclave. This issue is fixed in 0.5.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
源验证错误
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Privasys ra-tls-clients < 0.5.0 -

II. Public POCs for CVE-2026-108269

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-108269

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-108269 (2)

Vendor Advisories for CVE-2026-108269 (1)

Security Blog Posts for CVE-2026-108269 (1)

Same Patch Batch · Privasys · 2026-10-09 · 5 CVEs total

CVE-2026-108265 9.1 CRITICAL enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session
CVE-2026-108266 9.1 CRITICAL Privasys rustls fork: RA-TLS challenge mode did not bind attestation evidence to the TLS s
CVE-2026-108267 9.1 CRITICAL Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS sessi
CVE-2026-108268 9.1 CRITICAL enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session

IV. Related Vulnerabilities

V. Comments for CVE-2026-108269

No comments yet


Leave a comment