CVE-2026-108269
Received Received - Intake

Remote Attestation Bypass in RA-TLS Clients Prior to 0.5.0

Vulnerability report for CVE-2026-108269, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Remote Attestation TLS Clients provides multi-language utilities for verifying attested TLS connections. Prior to 0.5.0, the Rust and Go RA-TLS challenge verifiers accepted quote ReportData that was bound to the certificate public key and client nonce but not to the active TLS session before permitting application traffic. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing the clients to accept an attacker-terminated connection as the attested enclave. This issue is fixed in 0.5.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Privasys ra-tls-clients < 0.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Remote Attestation TLS Clients versions before 0.5.0. The Rust and Go implementations accepted quote ReportData tied to a certificate public key and client nonce but not to the active TLS session. This allowed attackers with a stolen enclave TLS private key to relay genuine quotes to other connections, tricking clients into accepting attacker-terminated connections as valid attested enclaves.

Detection Guidance

This vulnerability can be detected by checking if the installed version of ra-tls-clients is below 0.5.0. Use package managers like cargo or go to verify the version. For Rust, run cargo show ra-tls-clients. For Go, check go list -m all. If the version is older than 0.5.0, update immediately.

Impact Analysis

If you use affected versions of Remote Attestation TLS Clients, an attacker could impersonate an attested enclave by relaying legitimate quotes to unauthorized connections. This could lead to unauthorized access to sensitive data or systems under the guise of a trusted enclave.

Compliance Impact

This vulnerability could violate compliance requirements that mandate secure authentication and data integrity, such as GDPR's data protection principles or HIPAA's safeguards for protected health information. Accepting unauthorized connections may lead to data breaches or unauthorized access, triggering regulatory penalties.

Mitigation Strategies

Update Remote Attestation TLS Clients to version 0.5.0 or later to address the issue where ReportData was not bound to the active TLS session.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108269. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart