
🚨Critical - Privasys Go RA-TLS Quote Relay / Session Binding Bypass (CVE-2026-108267) Privasys Go’s RA-TLS challenge-mode in crypto/tls failed to bind attestation evidence (quote) to the active TLS session prior to privasys-v0.5.1-go1.26.5. With an enclave TLS private key, an attacker can relay a valid quote across connections, causing relying parties to accept an attacker-terminated handshake as an attested enclave session. 👉Affected: Privasys/go (privasys < v0.5.1-go1.26.5) | Upgrade to privasys-v0.5.1-go1.26.5
