CVE-2026-108266
Received Received - Intake

RA-TLS Challenge Certificate Relay in Privasys rustls

Vulnerability report for CVE-2026-108266, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Privasys rustls is a maintained fork of the rustls TLS library that adds RA-TLS challenge and channel-binding support. Prior to privasys-v0.8.1, the fork emitted RA-TLS challenge certificates whose quote ReportData was bound to the certificate public key and client nonce but not to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept an attacker-terminated connection as the attested enclave. This issue is fixed in privasys-v0.8.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Privasys rustls < privasys-v0.8.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Privasys rustls is a modified version of the rustls TLS library that supports RA-TLS challenge and channel-binding. Before version privasys-v0.8.1, it created RA-TLS challenge certificates where the quote ReportData was linked to the certificate public key and client nonce but not to the active TLS session. This allowed an attacker with an enclave TLS private key to replay a genuine quote on another connection, tricking a relying party into accepting a connection terminated by the attacker as a legitimate attested enclave.

Detection Guidance

This vulnerability affects Privasys rustls versions prior to v0.8.1. Detection involves checking the installed version of Privasys rustls. If the version is below v0.8.1, the system is vulnerable. No specific commands are provided in the context to detect active exploitation.

Impact Analysis

If you rely on RA-TLS for secure enclave attestation, an attacker could impersonate an attested enclave by replaying a valid quote. This could lead to unauthorized access to sensitive data or systems, as the attacker's connection would appear legitimate. Systems using older versions of privasys rustls are at risk until updated.

Compliance Impact

This vulnerability could undermine compliance with GDPR, HIPAA, and other regulations requiring secure authentication and data protection. By allowing unauthorized connections to appear legitimate, it may lead to data breaches or unauthorized access, violating confidentiality and integrity requirements.

Mitigation Strategies

Update privasys rustls to version 0.8.1 or later to address the RA-TLS challenge certificate issue. Ensure all enclave TLS private keys are rotated and revoked if compromised.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108266. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart