TLS Session Vulnerability in Privasys Go Programming Environment
CVE-2026-108267
9.1CRITICAL
What is CVE-2026-108267?
Privasys Go, a fork of the Go programming language with RA-TLS support, contains a vulnerability where challenge-mode RA-TLS certificates do not bind the ReportData to the active TLS session. This oversight allows an attacker with access to an enclave TLS private key to relay valid quotes on alternate connections. Consequently, a relying party may be misled into accepting a handshake as coming from a legitimate enclave connection, breaching the integrity of the connection. This flaw was addressed in the release of version privasys-v0.5.1-go1.26.5.
Affected Version(s)
go < privasys-v0.5.1-go1.26.5
