Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92701— Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path

Quick assessment

Affected
ultravioletrs cocos
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在受信任执行环境(TEE)中,在 0.8.2 及更早版本中,握手内已认证的 TLS(aTLS)Intel TDX 验证路径在验证报价(Quote)之前,未将当前会话的预期新鲜度值复制到 TDX 报价体策略中。因此,结构上有效的 TDX QuoteV4 证据(Evidence)会在未检查其 REPORT_DATA 字段是否与当前会话所期望的 reportData 匹配的情况下被接受。使用此路径的依赖方(relying party)可能会接受 reportData 不匹配或重复使用的证据,并在握手完成后释放应用数据,从

CVSS 9.1 · Critical EPSS 0.22% · P13

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle

Affected Version Matrix 1

VendorProduct Version RangeStatus
ultravioletrs cocos < 0.9.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92701

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path
Source: CVE Program / CVE List V5
Vulnerability Description
trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current session. A relying party using this path can therefore accept Evidence with a mismatched or reused reportData and release application data after the handshake, enabling session-misbinding to an unintended attestation context. The issue is fixed in version 0.9.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
源验证错误
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ultravioletrs cocos < 0.9.0 -

II. Public POCs for CVE-2026-92701

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92701

登录查看更多情报信息。

Other References for CVE-2026-92701 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92701

No comments yet


Leave a comment