Vulnerabilities/

dcap-qvl has Missing Verification for QE Identity

Severity:
High

Description

This vulnerability involves a critical gap in the cryptographic verification process within the dcap-qvl.

The library fetches QE Identity collateral (including qe_identity, qe_identity_signature, and qe_identity_issuer_chain) from the PCCS.

Recommendation

Update the @phala/dcap-qvl package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@phala/dcap-qvl
Anything's wrong? Let us know Last updated on January 29, 2026