Description
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation freshness when the expected reportData value is nil, empty, or omitted, leaving the SEV-SNP policy ReportData unset so the verifier accepts unrelated or stale Evidence not bound to the current connection. A relying party that uses this path without an expected reportData as a trust or authorization decision can be induced to trust an unintended attestation context; a supplied non-empty reportData is still validated. The issue is fixed in version 0.9.0.
Published: 2026-09-18
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Trust / Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker to bypass the freshness check in the AMD SEV‑SNP attestation path of Cocos AI’s intra‑handshake attested TLS. When the expected reportData is nil, empty, or omitted, the verifier accepts unrelated or stale evidence, effectively accepting an attestation that is not bound to the current connection. This can enable an attacker to convince the relying party that a different or outdated trust context is valid, leading to unauthorized trust or privilege escalation against the system. The weakness stems from improper validation of input data as described by CWE‑346.

Affected Systems

The flaw affects the Cocos AI confidential computing system from Ultravioletrs. Versions up to and including 0.8.2 are impacted. A fix was introduced in version 0.9.0, which enforces the required reportData presence and validity.

Risk and Exploitability

With a CVSS score of 9.1 the vulnerability is classified as critical. The EPSS score is below 1 %, indicating a low but non‑zero probability of exploitation in the wild. The issue is not yet listed in the CISA KEV catalog, but due to the high severity an attacker could attempt exploitation via a remote network connection establishing an attested TLS session. The exploit would require an attacker to supply evidence that bypasses the missing reportData verification, thereby inducing the system to accept a stale or unrelated attestation.

Generated by OpenCVE AI on September 19, 2026 at 15:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Cocos AI installation to version 0.9.0 or later to apply the fix that enforces reportData enforcement.
  • If an immediate upgrade is not feasible, explicitly configure the SEV‑SNP verification path to reject any evidence lacking a non‑empty reportData before proceeding with the session establishment.
  • Review all trust and authorization logic that relies on the intra‑handshake attested TLS path to ensure that reportData verification is performed, and adjust the code or policies to enforce this check.

Generated by OpenCVE AI on September 19, 2026 at 15:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Ultravioletrs
Ultravioletrs cocos
Vendors & Products Ultravioletrs
Ultravioletrs cocos

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation freshness when the expected reportData value is nil, empty, or omitted, leaving the SEV-SNP policy ReportData unset so the verifier accepts unrelated or stale Evidence not bound to the current connection. A relying party that uses this path without an expected reportData as a trust or authorization decision can be induced to trust an unintended attestation context; a supplied non-empty reportData is still validated. The issue is fixed in version 0.9.0.
Title Cocos AI: Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path
Weaknesses CWE-346
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ultravioletrs Cocos
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T15:05:43.497Z

Reserved: 2026-09-16T16:22:31.542Z

Link: CVE-2026-92702

cve-icon Vulnrichment

Updated: 2026-09-22T15:05:37.759Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T18:18:16.257

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-92702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:45:16Z

Weaknesses