Description
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current session. A relying party using this path can therefore accept Evidence with a mismatched or reused reportData and release application data after the handshake, enabling session-misbinding to an unintended attestation context. The issue is fixed in version 0.9.0.
Published: 2026-09-18
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Session misbinding enabling unauthorized data disclosure
Action: Apply patch
AI Analysis

Impact

The vulnerability allows the Intel TDX attested TLS verifier to accept a TDX QuoteV4 Evidence whose REPORT_DATA field does not match the expected freshness value for the current session because the verifier fails to copy the value into the quote-body policy before validation. A malicious or replayed quote can therefore be accepted, enabling a session‑misbinding attack where application data is released to an unintended attestation context. This flaw effectively bypasses the integrity guarantees normally provided by the attestation process.

Affected Systems

Ultravioletrs Cocos versions 0.8.2 and earlier are affected. The issue was addressed in release 0.9.0, which implements the missing REPORT_DATA check.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity attack affecting confidentiality and integrity. The EPSS score of less than 1% suggests the current probability of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to supply a malicious or replayed TDX Quote during a TLS handshake, a scenario that could be performed by an adversary with network or privileged access to the verifying application.

Generated by OpenCVE AI on September 21, 2026 at 15:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Cocos to version 0.9.0 or later, which adds the missing REPORT_DATA validation.
  • Ensure your deployment is configured to use the updated verifier path; verify that all aTLS handshakes invoke the patched component.
  • If an upgrade cannot be applied immediately, temporarily disable the Intel TDX verification path for the aTLS handshake until the patch is deployed.

Generated by OpenCVE AI on September 21, 2026 at 15:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current session. A relying party using this path can therefore accept Evidence with a mismatched or reused reportData and release application data after the handshake, enabling session-misbinding to an unintended attestation context. The issue is fixed in version 0.9.0. Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current session. A relying party using this path can therefore accept Evidence with a mismatched or reused reportData and release application data after the handshake, enabling session-misbinding to an unintended attestation context. The issue is fixed in version 0.9.0.

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Ultravioletrs
Ultravioletrs cocos
Vendors & Products Ultravioletrs
Ultravioletrs cocos

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current session. A relying party using this path can therefore accept Evidence with a mismatched or reused reportData and release application data after the handshake, enabling session-misbinding to an unintended attestation context. The issue is fixed in version 0.9.0.
Title Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path
Weaknesses CWE-346
CWE-354
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Ultravioletrs Cocos
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T14:05:58.274Z

Reserved: 2026-09-16T16:22:31.542Z

Link: CVE-2026-92701

cve-icon Vulnrichment

Updated: 2026-09-18T19:53:37.704Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T18:18:16.103

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-92701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T16:00:09Z

Weaknesses
  • CWE-346

    Origin Validation Error

  • CWE-354

    Improper Validation of Integrity Check Value