RA-TLS Channel-Binding Vulnerability in Privasys Rustls by Privasys
CVE-2026-108266
9.1CRITICAL
What is CVE-2026-108266?
The Privasys rustls fork, prior to version v0.8.1, contained a vulnerability in its RA-TLS challenge certificate handling. This flaw allowed an attacker with access to an enclave TLS private key to misuse genuine quote reports, effectively relaying them onto different connections. As a result, relying parties could be misled into accepting connections terminated by the attacker as legitimate enclave connections. This vulnerability was rectified in version v0.8.1, emphasizing the necessity of proper session binding in TLS implementations.
Affected Version(s)
rustls < privasys-v0.8.1
