CVE-2026-108267

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Privasys Go is a maintained fork of the Go programming language that adds RA-TLS support to crypto/tls. Prior to privasys-v0.5.1-go1.26.5, challenge-mode RA-TLS certificates bound quote ReportData to the certificate public key and client nonce but not to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept a handshake terminated by the attacker as an attested enclave connection. This issue is fixed in privasys-v0.5.1-go1.26.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-10: 110-10
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨Critical - Privasys Go RA-TLS Quote Relay / Session Binding Bypass (CVE-2026-108267) Privasys Go’s RA-TLS challenge-mode in crypto/tls failed to bind attestation evidence (quote) to the active TLS session prior to privasys-v0.5.1-go1.26.5. With an enclave TLS private key, an attacker can relay a valid quote across connections, causing relying parties to accept an attacker-terminated handshake as an attested enclave session. 👉Affected: Privasys/go (privasys < v0.5.1-go1.26.5) | Upgrade to privasys-v0.5.1-go1.26.5

    0000041
    315 followersView on X

Explore more