Insecure TLS Verification in Cocos by Ultravioletrs
CVE-2026-92701
9.1CRITICAL
What is CVE-2026-92701?
An issue in Cocos versions up to and including 0.8.2 allows for the acceptance of structurally valid TDX QuoteV4 Evidence without a thorough validation of the REPORT_DATA field. This flaw arises from the failure to transfer the expected current-session freshness value into the TDX quote-body policy prior to quote validation. As a result, a relying party can incorrectly accept evidence that has mismatched or reused reportData, potentially leading to session-misbinding within unintended attestation contexts. Users should upgrade to version 0.9.0 or later to mitigate this risk.
Affected Version(s)
cocos < 0.9.0
