[Ufmrg] EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing

Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de> Mon, 21 September 2026 14:48 UTC

Received: from mailout7.zih.tu-dresden.de (mailout7.zih.tu-dresden.de [141.76.32.220]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx.ietf.org (Postfix) with ESMTPS id ACC2831 for <ufmrg@irtf.org>; Mon, 21 Sep 2026 14:48:46 +0000 (UTC)
Authentication-Results: mx.ietf.org; dkim=pass header.d=tu-dresden.de header.s=dkim2022 header.b=Si7CWhmU; dmarc=pass (policy=none) header.from=tu-dresden.de; spf=pass (mx.ietf.org: domain of muhammad_usama.sardar@tu-dresden.de designates 141.76.32.220 as permitted sender) smtp.mailfrom=muhammad_usama.sardar@tu-dresden.de
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=tu-dresden.de; s=dkim2022; h=Content-Type:To:Subject:From:MIME-Version:Date :Message-ID:Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=Z9CUrIClKxBampfwyTP2BHk4vTigEyJWCc6gRum7oLI=; b=Si7CWhmU4BblirHCx4E7PE1/6t BHIf4hq0v2Qe9s+LppHtLIFwkyIir5jctK4gjrApeJler63Qv0ZmXECD49JuuDaTaG8XE0vWSJDXh Y1Jrji/yNk7yue9oK9LMblKE+WmcBO5sNIMdFsA+021DoUWV/rJcEd/A3++QbBSrhg/KCJ4z9Rzu1 Z1DCbNg80QDVDnRaJeBQ3kebSNXtxMJ3m01hO2hb4Jlhab2O9HTYAJhj33U3oexuHjE8NxPbHMl5X f+szjfGT4V22dm0R8E4iIwFmMyKSGsDp0LzMNhz0tRQWFWI9BK1XJZkYRgrQ+XOOFzFV667Mz83AI 5IEjxDOg==;
Received: from msx-t422.msx.ad.zih.tu-dresden.de ([172.26.35.139] helo=msx.tu-dresden.de) by mailout7.zih.tu-dresden.de with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <muhammad_usama.sardar@tu-dresden.de>) id 1x8fJr-000TtO-1S for ufmrg@irtf.org; Mon, 21 Sep 2026 16:48:39 +0200
Received: from [10.12.5.228] (141.76.13.149) by msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.49; Mon, 21 Sep 2026 16:48:27 +0200
Message-ID: <4b968f77-631e-4d26-a86d-280dd9aee66e@tu-dresden.de>
Date: Mon, 21 Sep 2026 16:48:27 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-US
From: Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de>
To: UFMRG IRTF <ufmrg@irtf.org>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-512"; boundary="------------ms050004050502020909020607"
X-ClientProxiedBy: MSX-L415.msx.ad.zih.tu-dresden.de (172.26.34.135) To msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139)
X-TUD-Virus-Scanned: mailout7.zih.tu-dresden.de
X-Spamd-Bar: ----
Message-ID-Hash: RSY2M3HHPW4NMUGKGHJZ47AJHFMRPYVT
X-Message-ID-Hash: RSY2M3HHPW4NMUGKGHJZ47AJHFMRPYVT
X-MailFrom: muhammad_usama.sardar@tu-dresden.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [Ufmrg] EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing
List-Id: Usable Formal Methods Research Group <ufmrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ufmrg/ZQKdp07P4UeTushAC1q9eBBtp0s>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ufmrg>
List-Help: <mailto:ufmrg-request@irtf.org?subject=help>
List-Owner: <mailto:ufmrg-owner@irtf.org>
List-Post: <mailto:ufmrg@irtf.org>
List-Subscribe: <mailto:ufmrg-join@irtf.org>
List-Unsubscribe: <mailto:ufmrg-leave@irtf.org>

Hi all,

# *Context*

At SEAL chartering time, IESG (e.g., [0]) and IETF participants (e.g., 
[1]) requested operational guidance for attested TLS. We did some 
relevant formal analysis and would like to share our paper presenting 
the results of our analysis with the RG for feedback and for information 
of other implementers to secure their systems.

# *Key Findings*

Our paper covers the following two implementations of early attestation:

## *1. Ultraviolet Cocos AI*

Ultraviolet claimed to be the most secure attested TLS solution in 
Confidential Computing Consortium (CCC). We discovered two 
critical-severity [2] (CVSS 9.1) vulnerabilities in their implementation 
of early attestation. Published GitHub Security Advisories (GHSAs) [3,4] 
are quite detailed and explicitly cite arguments against 
draft-fossati-seat-early-attestation. So we won't repeat that here.

Moreover, two CVEs of CVSS 9.1 have been issued: CVE-2026-92701 [5] and 
CVE-2026-92702 [6].

## *2. Edgeless Systems Contrast*

Edgeless Systems was awarded second place in the cybersecurity category 
of the WirtschaftsWoche’s well-known "Best of Technology Awards" this 
year [7]. We analyzed its attested TLS solution named Contrast, and 
found a critical vulnerability in the CVSS range 9.0 to the maximum 
possible 10.0. GHSA on this is published [8].

# *Discovery Methodology*

  * Formal analysis using state-of-the-art tool ProVerif
  * Implementation-level regression tests for confirmation
  * Reviewed and confirmed by developers
  * GHSAs published [3,4]
  * CVEs issued [5,6]
  * Contrast maintainers have requested CVE for GHSA [8]; review by
    GitHub is in progress for issuing the CVE

# *Ethical Considerations*

We kept the vulnerabilities under strict /responsible disclosure/ until 
confirmed and published by the developers. Cocos AI has moved to 
post-handshake attestation, while Edgeless Systems currently maintains 
early attestation.

# *Paper*

Please see [9].

# *Acknowledgments*

  * Cocos AI maintainers (Sammy Kerata Oina and Drasko Draskovic)
  * Edgeless Systems Contrast maintainer (Markus Rudy)
  * Bertrand Foing
  * Rebekah Overdorf and Tobias Pulls

We welcome any feedback and collaborators for further research on this 
topic. We surely need your help.

Best regards,

-Usama and Songbo


PS: The name is inspired from Heartbleed, which was CVSS 7.5. CVSS 9.1 
and 9.0-10.0 is surely more bleeding than Heartbleed.


[0] https://mailarchive.ietf.org/arch/msg/seal/BJmfAFQxap4tDNfNbCbhRfGwJ3s/

[1] https://mailarchive.ietf.org/arch/msg/seal/oNtTWnQ409zxqYYbWHNeUflcC3s/

[2] https://nvd.nist.gov/vuln-metrics/cvss

[3] 
https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47

[4] 
https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw

[5] https://www.cve.org/CVERecord?id=CVE-2026-92701

[6] https://www.cve.org/CVERecord?id=CVE-2026-92702

[7] https://award.wiwo.de/bot/gewinner-2026/

[8] 
https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898

[9] 
https://www.researchgate.net/publication/414529199_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing