Description
This vulnerability involves a critical gap in the cryptographic verification process within the dcap-qvl.
The library fetches QE Identity collateral (including qe_identity, qe_identity_signature, and qe_identity_issuer_chain) from the PCCS.
Recommendation
Update the @phala/dcap-qvl package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.3.0
- Patched version(s): 0.3.9
References
Related Issues
- OneUptime WhatsApp Webhook Missing Signature Verification - CVE-2026-33143
- OneUptime has WhatsApp Resend Verification Authorization Bypass - CVE-2026-30959
- Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability - CVE-2026-44211
- SCEditor has DOM XSS via emoticon URL/HTML injection - CVE-2026-25581
You might also like:
- Tags:
- npm
- @phala/dcap-qvl
Anything's wrong? Let us know Last updated on January 29, 2026


