VYPR
Vendor

Privasys

Products
6
CVEs
5
Across products
6
Status
Private

Products

6

Recent CVEs

5
  • CVE-2026-108269CriOct 9, 2026
    risk 0.52cvss —epss —

    Remote Attestation TLS Clients provides multi-language utilities for verifying attested TLS connections. Prior to 0.5.0, the Rust and Go RA-TLS challenge verifiers accepted quote ReportData that was bound to the certificate public key and client nonce but not to the active TLS…

  • CVE-2026-108268CriOct 9, 2026
    risk 0.52cvss —epss —

    Enclave OS Virtual runs container workloads inside confidential virtual machines with end-to-end attestation. Prior to tdx-v0.2.43 and tdx-gpu-v0.6.27, the TDX/GPU RA-TLS certificate issuer placed the certificate public-key hash and client nonce in quote ReportData but omitted a…

  • CVE-2026-108267CriOct 9, 2026
    risk 0.52cvss —epss —

    Privasys Go is a maintained fork of the Go programming language that adds RA-TLS support to crypto/tls. Prior to privasys-v0.5.1-go1.26.5, challenge-mode RA-TLS certificates bound quote ReportData to the certificate public key and client nonce but not to the active TLS session.…

  • CVE-2026-108266CriOct 9, 2026
    risk 0.52cvss —epss —

    Privasys rustls is a maintained fork of the rustls TLS library that adds RA-TLS challenge and channel-binding support. Prior to privasys-v0.8.1, the fork emitted RA-TLS challenge certificates whose quote ReportData was bound to the certificate public key and client nonce but not…

  • CVE-2026-108265CriOct 9, 2026
    risk 0.52cvss —epss —

    Enclave OS Mini is a Rust-based runtime for confidential applications inside Intel SGX enclaves. Prior to wasm-v0.40.0, the SGX runtime's RA-TLS challenge certificate path placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to…