{"id":"CVE-2026-108265","summary":"enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session","details":"Enclave OS Mini is a Rust-based runtime for confidential applications inside Intel SGX enclaves. Prior to wasm-v0.40.0, the SGX runtime's RA-TLS challenge certificate path placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept an attacker-terminated connection as the attested enclave. This issue is fixed in wasm-v0.40.0.","aliases":["GHSA-49qm-4pj3-w2c6"],"modified":"2026-10-10T10:45:27.603085287Z","published":"2026-10-09T20:55:54.705Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-346"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108265.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108265.json"},{"type":"FIX","url":"https://github.com/Privasys/enclave-os-mini/commit/9f541c849ef733d2df2851a666f359d01dcdcb8e"},{"type":"WEB","url":"https://github.com/Privasys/enclave-os-mini/releases/tag/wasm-v0.40.0"},{"type":"ADVISORY","url":"https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-108265"},{"type":"ARTICLE","url":"https://privasys.org/blog/binding-attestation-to-the-tls-session"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/privasys/enclave-os-mini","events":[{"introduced":"0"},{"fixed":"553927f9cbd71ece1c6dbb538c2dd14bef95c65a"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"wasm-v0.40.0"}]}}],"versions":["wasm-v0.39.0","wasm-v0.38.0","wasm-v0.37.0","wasm-v0.36.0","wasm-v0.35.0","wasm-v0.34.0","wasm-v0.33.0","wasm-v0.32.0","v0.22.0","v0.21.0","v0.20.3","v0.20.2","v0.20.1","v0.20.0","wasm-v0.31.0","wasm-v0.30.0","wasm-v0.29.0","wasm-v0.28.0","wasm-v0.27.0","wasm-v0.26.0","wasm-v0.25.0","wasm-v0.24.0","wasm-v0.23.0","wasm-v0.22.0","wasm-v0.21.1","wasm-v0.20.1","wasm-v0.21.0","wasm-v0.20.0","wasm-v0.18.3","v0.19.1","v0.19.0","v0.18.3","v0.18.2","v0.18.1","v0.18.0","v0.17.5","v0.17.4","v0.17.3","v0.17.2","v0.17.1","v0.17.0","v0.16.1","v0.16.0","v0.15.0","v0.14.0","v0.12.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108265.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}