TLS Session Vulnerability in Privasys Go Programming Environment
CVE-2026-108267

9.1CRITICAL

Key Information:

Vendor

Privasys

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-108267?

Privasys Go, a fork of the Go programming language with RA-TLS support, contains a vulnerability where challenge-mode RA-TLS certificates do not bind the ReportData to the active TLS session. This oversight allows an attacker with access to an enclave TLS private key to relay valid quotes on alternate connections. Consequently, a relying party may be misled into accepting a handshake as coming from a legitimate enclave connection, breaching the integrity of the connection. This flaw was addressed in the release of version privasys-v0.5.1-go1.26.5.

Affected Version(s)

go < privasys-v0.5.1-go1.26.5

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.