CVE-2026-92702: CWE-346: Origin Validation Error in ultravioletrs cocos
CVE-2026-92702 is a critical origin validation vulnerability in ultravioletrs cocos, a confidential computing system for AI workloads. Versions up to and including 0.8.2 do not enforce attestation freshness in the intra-handshake attested TLS AMD SEV-SNP verification path when the expected reportData is nil, empty, or omitted. This allows acceptance of unrelated or stale attestation evidence, potentially causing a relying party to trust an unintended attestation context. The issue is fixed in version 0.9.0.
AI Analysis
Technical Summary
The vulnerability in ultravioletrs cocos affects the attested TLS (aTLS) AMD SEV-SNP verification path used in confidential computing for AI workloads. Specifically, when the expected reportData value is nil, empty, or omitted, the SEV-SNP policy ReportData is unset, causing the verifier to accept stale or unrelated attestation evidence not bound to the current connection. This flaw allows a relying party that uses this verification path without an expected reportData to be induced to trust an unintended attestation context. If a non-empty reportData is supplied, validation occurs correctly. The flaw is addressed in version 0.9.0.
Potential Impact
An attacker can cause a relying party to trust stale or unrelated attestation evidence, potentially leading to unauthorized trust or authorization decisions. This compromises the integrity of the attestation process in confidential computing environments, risking unauthorized access or misuse of AI workloads running inside trusted execution environments. The vulnerability has a CVSS 3.1 score of 9.1, indicating critical impact on confidentiality and integrity without affecting availability.
Mitigation Recommendations
Upgrade to ultravioletrs cocos version 0.9.0 or later, where this vulnerability is fixed. The vendor advisory confirms the issue is resolved in version 0.9.0. No other mitigation steps are specified or required.
CVE-2026-92702: CWE-346: Origin Validation Error in ultravioletrs cocos
Description
CVE-2026-92702 is a critical origin validation vulnerability in ultravioletrs cocos, a confidential computing system for AI workloads. Versions up to and including 0.8.2 do not enforce attestation freshness in the intra-handshake attested TLS AMD SEV-SNP verification path when the expected reportData is nil, empty, or omitted. This allows acceptance of unrelated or stale attestation evidence, potentially causing a relying party to trust an unintended attestation context. The issue is fixed in version 0.9.0.
CVSS v3.1
Score 9.1critical
Affected software
ultravioletrs
cocos
pkg:github/ultravioletrs/cocosRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in ultravioletrs cocos affects the attested TLS (aTLS) AMD SEV-SNP verification path used in confidential computing for AI workloads. Specifically, when the expected reportData value is nil, empty, or omitted, the SEV-SNP policy ReportData is unset, causing the verifier to accept stale or unrelated attestation evidence not bound to the current connection. This flaw allows a relying party that uses this verification path without an expected reportData to be induced to trust an unintended attestation context. If a non-empty reportData is supplied, validation occurs correctly. The flaw is addressed in version 0.9.0.
Potential Impact
An attacker can cause a relying party to trust stale or unrelated attestation evidence, potentially leading to unauthorized trust or authorization decisions. This compromises the integrity of the attestation process in confidential computing environments, risking unauthorized access or misuse of AI workloads running inside trusted execution environments. The vulnerability has a CVSS 3.1 score of 9.1, indicating critical impact on confidentiality and integrity without affecting availability.
Mitigation Recommendations
Upgrade to ultravioletrs cocos version 0.9.0 or later, where this vulnerability is fixed. The vendor advisory confirms the issue is resolved in version 0.9.0. No other mitigation steps are specified or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-16T16:22:31.542Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aad759f55bf5e2cf54f35d8
Added to database: 09/18/2026, 17:32:15 UTC
Last enriched: 09/18/2026, 17:46:39 UTC
Last updated: 09/18/2026, 18:36:05 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.