CVE-2026-33697 details a high-severity relay attack vulnerability within the attested TLS (aTLS) implementation of Cocos AI, impacting all versions from v0.4.0 through v0.8.2 across both AMD SEV-SNP and Intel TDX deployment targets. This architectural flaw allows an attacker to extract the ephemeral TLS private key, typically through physical access or side-channel attacks, enabling them to impersonate a genuine Cocos AI service. Successful exploitation undermines authentication guarantees, allowing the attacker to access sensitive data or operations intended for the legitimate endpoint, leading to high confidentiality and integrity impacts (CVSS 7.5). While no patch or complete workaround is currently available, there is no evidence of active exploitation, nor are public exploit codes or significant community discussion reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.4.0, < 0.9.0CPE matchmatch criteria | cpe:2.3:a:ultraviolet:cocos_ai:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.