CVE-2026-108265
Received Received - Intake

SGX Enclave OS Mini TLS Session Relay Vulnerability

Vulnerability report for CVE-2026-108265, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Enclave OS Mini is a Rust-based runtime for confidential applications inside Intel SGX enclaves. Prior to wasm-v0.40.0, the SGX runtime's RA-TLS challenge certificate path placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept an attacker-terminated connection as the attested enclave. This issue is fixed in wasm-v0.40.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Privasys enclave-os-mini < wasm-v0.40.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Enclave OS Mini, a Rust-based runtime for confidential applications in Intel SGX enclaves. Before version wasm-v0.40.0, the SGX runtime's RA-TLS challenge certificate path did not properly bind the certificate public-key hash and client nonce to the active TLS session. This allowed an attacker with an enclave TLS private key to relay a genuine quote to another connection, tricking a relying party into accepting a malicious connection as a legitimate attested enclave.

Detection Guidance

This vulnerability involves improper binding of TLS session data in SGX enclave attestation. Detection requires checking if the affected Enclave OS Mini version (before wasm-v0.40.0) is running and verifying RA-TLS certificate handling. No specific commands are provided in the context to detect this issue.

Impact Analysis

If you use Enclave OS Mini prior to wasm-v0.40.0, an attacker could intercept or manipulate communications with your enclave by exploiting this vulnerability. This could lead to unauthorized access, data breaches, or impersonation of your attested enclave, compromising the confidentiality and integrity of your application's data and operations.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by enabling unauthorized access to sensitive data or systems. It undermines the integrity of attested enclaves, which are often used to protect personal or health information, potentially leading to legal and regulatory penalties due to data exposure or loss of confidentiality.

Mitigation Strategies

Update Enclave OS Mini to wasm-v0.40.0 or later to address the missing TLS session binding in RA-TLS challenge certificates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108265. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart