Origin Validation Error Affecting github.com/ultravioletrs/cocos/agent package, versions >=0.4.0 <0.9.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.01% (1st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMULTRAVIOLETRSCOCOSAGENT-15857200
  • published31 Mar 2026
  • disclosed27 Mar 2026
  • creditDr. Viacheslav Dubeyko, Prof. Jean-Marie Jacquet

Introduced: 27 Mar 2026

CVE-2026-33697  (opens in a new tab)
CWE-322  (opens in a new tab)
CWE-346  (opens in a new tab)

How to fix?

Upgrade github.com/ultravioletrs/cocos/agent to version 0.9.0 or higher.

Overview

Affected versions of this package are vulnerable to Origin Validation Error during the intra-handshake attestation.. An attacker can impersonate a trusted service endpoint and gain unauthorized access to sensitive data or operations by extracting the ephemeral TLS private key through physical access, transient execution, or side-channel attacks. This is only exploitable if the attacker is able to obtain the ephemeral TLS private key from the target environment.

Workaround

This vulnerability can be mitigated by keeping TEE firmware and microcode up to date, defining strict attestation policies that validate all available report fields, and enabling mutual attested TLS with CA-signed certificates where possible, though these measures do not fully eliminate the risk.

CVSS Base Scores

version 4.0
version 3.1