CVE-2026-108267
Received Received - Intake

Remote Attestation Bypass in Privasys Go

Vulnerability report for CVE-2026-108267, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Privasys Go is a maintained fork of the Go programming language that adds RA-TLS support to crypto/tls. Prior to privasys-v0.5.1-go1.26.5, challenge-mode RA-TLS certificates bound quote ReportData to the certificate public key and client nonce but not to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept a handshake terminated by the attacker as an attested enclave connection. This issue is fixed in privasys-v0.5.1-go1.26.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Privasys go < privasys-v0.5.1-go1.26.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Privasys Go is a modified version of the Go programming language with added RA-TLS support. Before version privasys-v0.5.1-go1.26.5, certificates used in challenge-mode RA-TLS did not properly bind quote ReportData to the TLS session. This allowed attackers with access to an enclave TLS private key to relay genuine quotes to other connections, tricking systems into accepting unauthenticated handshakes as valid attested enclave connections.

Detection Guidance

Detection requires checking if Privasys Go versions prior to privasys-v0.5.1-go1.26.5 are in use. Inspect Go module files or binaries for the vulnerable version. No specific commands are provided in the context.

Impact Analysis

If exploited, this vulnerability could allow an attacker to impersonate an attested enclave, potentially gaining unauthorized access to sensitive systems or data. Organizations using Privasys Go with RA-TLS prior to privasys-v0.5.1-go1.26.5 are at risk of man-in-the-middle attacks or unauthorized session hijacking.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles or HIPAA's security requirements. Compliance may be compromised if systems fail to ensure proper attestation and session binding, potentially resulting in data breaches and regulatory penalties.

Mitigation Strategies

Upgrade Privasys Go to version privasys-v0.5.1-go1.26.5 or later. Replace any enclave TLS private keys that may have been exposed. Review and revoke any certificates issued with the vulnerable version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108267. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart