Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-92701: Cocos AI may give data to wrong secure session
CVE-2026-92701 · published 10 days ago
Summary
Versions of Cocos AI up to 0.8.2 can accept a false proof that a trusted environment is valid, which may cause the system to release AI results to the wrong recipient or reuse old proof. This could allow an attacker to obtain or redirect sensitive data. Upgrading to version 0.9.0 fixes the problem.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ultravioletrs | cocos | < 0.9.0 |
Original advisory text
Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current session. A relying party using this path can therefore accept Evidence with a mismatched or reused reportData and release application data after the handshake, enabling session-misbinding to an unintended attestation context. The issue is fixed in version 0.9.0.
References
- https://github.com/ultravioletrs/cocos/releases/tag/v0.9.0
- https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92701... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92701 Vendor Advisory
Severity
9.1
Critical
CVSS 3.1: 9.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-346Origin Validation Error
CWE-354Improper Validation of Integrity Check Value
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Track software like this
Free during beta