dcap-qvl has Missing Verification for QE Identity
Published Jan 26, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.21%
Description
dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present in versions prior to 0.3.9 involves a critical gap in the cryptographic verification process within the dcap-qvl. The library fetches QE Identity collateral (including qe_identity, qe_identity_signature, and qe_identity_issuer_chain) from the PCCS. However, it skips to verify the QE Identity signature against its certificate chain and does not enforce policy constraints on the QE Report. An attacker can forge the QE Identity data to whitelist a malicious or non-Intel Quoting Enclave. This allows the attacker to forge the QE and sign untrusted quotes that the verifier will accept as valid. Effectively, this bypasses the entire remote attestation security model, as the verifier can no longer trust the entity responsible for signing the quotes. All deployments utilizing the dcap-qvl library for SGX or TDX quote verification are affected. The vulnerability has been patched in dcap-qvl version 0.3.9. The fix implements the missing cryptographic verification for the QE Identity signature and enforces the required checks for MRSIGNER, ISVPRODID, and ISVSVN against the QE Report. Users of the `@phala/dcap-qvl-node` and `@phala/dcap-qvl-web` packages should switch to the pure JavaScript implementation, `@phala/dcap-qvl`. There are no known workarounds for this vulnerability. Users must upgrade to the patched version to ensure that QE Identity collateral is properly verified.
Affected products
-
- Version < 0.3.9StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Phala-Network | Dcap-Qvl | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
dcap-qvl
crates.io
Introduced 0 Fixed 0.3.9@phala/dcap-qvl
npm
Introduced 0 Fixed 0.3.9@phala/dcap-qvl-web
npm
Introduced 0 Fixed not fixed@phala/dcap-qvl-node
npm
Introduced 0 Fixed not fixeddcap-qvl
PyPI
Introduced 0 Fixed 0.3.9
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| crates.io | dcap-qvl | 0 | 0.3.9 |
| npm | @phala/dcap-qvl | 0 | 0.3.9 |
| npm | @phala/dcap-qvl-web | 0 | not fixed |
| npm | @phala/dcap-qvl-node | 0 | not fixed |
| PyPI | dcap-qvl | 0 | 0.3.9 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Jan 27, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jan–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.21% (0.00208) | 9.80th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.21% (0.00208) | 10.88th | v5 (v2026.06.15) |
| Jan 27, 2026 | 0.02% (0.00016) | 2.85th | v4 (v2025.03.14) |
References (3)
- https://github.com/Phala-Network/dcap-qvl/security/advisories/GHSA-796p-j2gh-9m2q x_refsource_CONFIRM
- https://github.com/advisories/GHSA-796p-j2gh-9m2q Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-22696
| Link | Providers | Tags |
|---|---|---|
| https://github.com/Phala-Network/dcap-qvl/security/advisories/GHSA-796p-j2gh-9m2q | x_refsource_CONFIRM | |
| https://github.com/advisories/GHSA-796p-j2gh-9m2q | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-22696 |
Change history (0)
No recorded changes yet.