CVE-2026-33697 is an architectural weakness in Cocos AI's attested TLS (aTLS) implementation affecting all versions from v0.4.0 through v0.8.2, including both AMD SEV-SNP and Intel TDX deployment targets. During intra-handshake attestation, the attestation evidence is bound to the ephemeral TLS key, but not to the full TLS channel or application-data channel. If an attacker can obtain the ephemeral TLS private key used for that handshake, the attacker can relay or divert the session while presenting valid attestation evidence originating from the genuine attested service. As a result, the client accepts the connection under false assumptions about the endpoint identity: the attestation proves properties of a genuine attested service, but does not distinguish that service from an attacker-controlled relay endpoint. The issue is described as architectural and remains present despite the aTLS redesign introduced in v0.7.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity vulnerability in attested TLS / remote attestation for confidential computing TEEs that allows diversion or relay attacks, where a client validates a legitimate attested server but is silently redirected and encrypts data to a malicious machine.
A high-severity vulnerability in intra-handshake attestation / attested TLS that enables relay attacks, allowing a client to validate genuine attestation evidence but encrypt traffic to a different malicious machine instead.
A high-severity relay-attack vulnerability in intra-handshake attested TLS / attested TLS implementations for confidential computing, where a client can validate genuine attestation evidence yet have its connection silently redirected to a different malicious machine.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.