[Ufmrg] EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing
Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de> Mon, 21 September 2026 14:48 UTC
Received: from mailout7.zih.tu-dresden.de (mailout7.zih.tu-dresden.de [141.76.32.220]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx.ietf.org (Postfix) with ESMTPS id ACC2831 for <ufmrg@irtf.org>; Mon, 21 Sep 2026 14:48:46 +0000 (UTC)
Authentication-Results: mx.ietf.org; dkim=pass header.d=tu-dresden.de header.s=dkim2022 header.b=Si7CWhmU; dmarc=pass (policy=none) header.from=tu-dresden.de; spf=pass (mx.ietf.org: domain of muhammad_usama.sardar@tu-dresden.de designates 141.76.32.220 as permitted sender) smtp.mailfrom=muhammad_usama.sardar@tu-dresden.de
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=tu-dresden.de; s=dkim2022; h=Content-Type:To:Subject:From:MIME-Version:Date :Message-ID:Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=Z9CUrIClKxBampfwyTP2BHk4vTigEyJWCc6gRum7oLI=; b=Si7CWhmU4BblirHCx4E7PE1/6t BHIf4hq0v2Qe9s+LppHtLIFwkyIir5jctK4gjrApeJler63Qv0ZmXECD49JuuDaTaG8XE0vWSJDXh Y1Jrji/yNk7yue9oK9LMblKE+WmcBO5sNIMdFsA+021DoUWV/rJcEd/A3++QbBSrhg/KCJ4z9Rzu1 Z1DCbNg80QDVDnRaJeBQ3kebSNXtxMJ3m01hO2hb4Jlhab2O9HTYAJhj33U3oexuHjE8NxPbHMl5X f+szjfGT4V22dm0R8E4iIwFmMyKSGsDp0LzMNhz0tRQWFWI9BK1XJZkYRgrQ+XOOFzFV667Mz83AI 5IEjxDOg==;
Received: from msx-t422.msx.ad.zih.tu-dresden.de ([172.26.35.139] helo=msx.tu-dresden.de) by mailout7.zih.tu-dresden.de with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <muhammad_usama.sardar@tu-dresden.de>) id 1x8fJr-000TtO-1S for ufmrg@irtf.org; Mon, 21 Sep 2026 16:48:39 +0200
Received: from [10.12.5.228] (141.76.13.149) by msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.49; Mon, 21 Sep 2026 16:48:27 +0200
Message-ID: <4b968f77-631e-4d26-a86d-280dd9aee66e@tu-dresden.de>
Date: Mon, 21 Sep 2026 16:48:27 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-US
From: Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de>
To: UFMRG IRTF <ufmrg@irtf.org>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-512"; boundary="------------ms050004050502020909020607"
X-ClientProxiedBy: MSX-L415.msx.ad.zih.tu-dresden.de (172.26.34.135) To msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139)
X-TUD-Virus-Scanned: mailout7.zih.tu-dresden.de
X-Spamd-Bar: ----
Message-ID-Hash: RSY2M3HHPW4NMUGKGHJZ47AJHFMRPYVT
X-Message-ID-Hash: RSY2M3HHPW4NMUGKGHJZ47AJHFMRPYVT
X-MailFrom: muhammad_usama.sardar@tu-dresden.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [Ufmrg] EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing
List-Id: Usable Formal Methods Research Group <ufmrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ufmrg/ZQKdp07P4UeTushAC1q9eBBtp0s>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ufmrg>
List-Help: <mailto:ufmrg-request@irtf.org?subject=help>
List-Owner: <mailto:ufmrg-owner@irtf.org>
List-Post: <mailto:ufmrg@irtf.org>
List-Subscribe: <mailto:ufmrg-join@irtf.org>
List-Unsubscribe: <mailto:ufmrg-leave@irtf.org>
Hi all,
# *Context*
At SEAL chartering time, IESG (e.g., [0]) and IETF participants (e.g.,
[1]) requested operational guidance for attested TLS. We did some
relevant formal analysis and would like to share our paper presenting
the results of our analysis with the RG for feedback and for information
of other implementers to secure their systems.
# *Key Findings*
Our paper covers the following two implementations of early attestation:
## *1. Ultraviolet Cocos AI*
Ultraviolet claimed to be the most secure attested TLS solution in
Confidential Computing Consortium (CCC). We discovered two
critical-severity [2] (CVSS 9.1) vulnerabilities in their implementation
of early attestation. Published GitHub Security Advisories (GHSAs) [3,4]
are quite detailed and explicitly cite arguments against
draft-fossati-seat-early-attestation. So we won't repeat that here.
Moreover, two CVEs of CVSS 9.1 have been issued: CVE-2026-92701 [5] and
CVE-2026-92702 [6].
## *2. Edgeless Systems Contrast*
Edgeless Systems was awarded second place in the cybersecurity category
of the WirtschaftsWoche’s well-known "Best of Technology Awards" this
year [7]. We analyzed its attested TLS solution named Contrast, and
found a critical vulnerability in the CVSS range 9.0 to the maximum
possible 10.0. GHSA on this is published [8].
# *Discovery Methodology*
* Formal analysis using state-of-the-art tool ProVerif
* Implementation-level regression tests for confirmation
* Reviewed and confirmed by developers
* GHSAs published [3,4]
* CVEs issued [5,6]
* Contrast maintainers have requested CVE for GHSA [8]; review by
GitHub is in progress for issuing the CVE
# *Ethical Considerations*
We kept the vulnerabilities under strict /responsible disclosure/ until
confirmed and published by the developers. Cocos AI has moved to
post-handshake attestation, while Edgeless Systems currently maintains
early attestation.
# *Paper*
Please see [9].
# *Acknowledgments*
* Cocos AI maintainers (Sammy Kerata Oina and Drasko Draskovic)
* Edgeless Systems Contrast maintainer (Markus Rudy)
* Bertrand Foing
* Rebekah Overdorf and Tobias Pulls
We welcome any feedback and collaborators for further research on this
topic. We surely need your help.
Best regards,
-Usama and Songbo
PS: The name is inspired from Heartbleed, which was CVSS 7.5. CVSS 9.1
and 9.0-10.0 is surely more bleeding than Heartbleed.
[0] https://mailarchive.ietf.org/arch/msg/seal/BJmfAFQxap4tDNfNbCbhRfGwJ3s/
[1] https://mailarchive.ietf.org/arch/msg/seal/oNtTWnQ409zxqYYbWHNeUflcC3s/
[2] https://nvd.nist.gov/vuln-metrics/cvss
[3]
https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47
[4]
https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw
[5] https://www.cve.org/CVERecord?id=CVE-2026-92701
[6] https://www.cve.org/CVERecord?id=CVE-2026-92702
[7] https://award.wiwo.de/bot/gewinner-2026/
[8]
https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898
[9]
https://www.researchgate.net/publication/414529199_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing
- [Ufmrg] EarlyAttestationBleed: Three Critical-sev… Muhammad Usama Sardar
- [Ufmrg] Re: EarlyAttestationBleed: Three Critical… Songbo Bu