CVE-2026-108267

Source
https://cve.org/CVERecord?id=CVE-2026-108267
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108267.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-108267
Aliases
  • GHSA-7jfw-53rm-phh2
Published
2026-10-09T21:11:33Z
Modified
2026-10-11T02:49:40Z
Severity
  • 9.1 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session
Details

Privasys Go is a maintained fork of the Go programming language that adds RA-TLS support to crypto/tls. Prior to privasys-v0.5.1-go1.26.5, challenge-mode RA-TLS certificates bound quote ReportData to the certificate public key and client nonce but not to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept a handshake terminated by the attacker as an attested enclave connection. This issue is fixed in privasys-v0.5.1-go1.26.5.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-346"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108267.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "privasys-v0.5.1-go1.26.5"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/privasys/go

Affected ranges

Type
GIT
Repo
https://github.com/privasys/go
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

privasys-v0.*
privasys-v0.3.0-go1.26.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108267.json"