Description
This vulnerability involves a critical gap in the cryptographic verification process within the dcap-qvl.
The library fetches QE Identity collateral (including qe_identity, qe_identity_signature, and qe_identity_issuer_chain) from the PCCS.
Recommendation
Update the @phala/dcap-qvl package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.3.0
- Patched version(s): 0.3.9
References
Could your website be exposed too?
SmartScanner can check your website for dcap-qvl has Missing Verification for QE Identity and gives you actionable findings to investigate.
Start a free scanRelated Issues
- OneUptime WhatsApp Webhook Missing Signature Verification - CVE-2026-33143
- OneUptime has WhatsApp Resend Verification Authorization Bypass - CVE-2026-30959
- Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability - CVE-2026-44211
- SCEditor has DOM XSS via emoticon URL/HTML injection - CVE-2026-25581


