Skip to main content

HyperLink AWS Nitro TEE

Type

Security review

Client

HyperLink

Date

2026-03

Domain

Crypto

Effort

2.2 wks

Section

Cryptography Reviews

Trail of Bits's security review of HyperLink (Mar 2026) identified 24 issues: 3 high, 7 medium, 9 low, and 5 informational.

Findings · 24

  1. 1 Prover enclave public key not validated against attested public key Medium
  2. 2 Unauthenticated ephemeral key exchange enables parent MITM attacks Medium
  3. 3 Attestation verification missing from important operator flows Medium
  4. 4 Deficiencies in the enclave registration and attestation processes High
  5. 5 KMS key policy only validates PCR0 Low
  6. 6 X25519 shared secret used directly without key derivation function Low
  7. 7 Missing length validation in key exchange response may cause denial of service Low
  8. 8 Incomplete attestation document validation against AWS Nitro specification Medium
  9. 9 Missing extension constraint validation in certificate chain verification Informational
  10. 10 Storage download accepts unbounded allocation size Medium
  11. 11 Storage rollback attack on database snapshots High
  12. 12 Backup timestamp not validated during recovery Informational
  13. 13 Potential integer truncation in database sync Informational
  14. 14 Missing secret version validation may allow stale credential usage Low
  15. 15 Clock source verification only logs warning Low
  16. 16 Documented client-to-enclave encryption not implemented Medium
  17. 17 Missing signature algorithm validation in X.509 chain verification Informational
  18. 18 Certificate validity boundary check non-compliance with RFC 5280 Informational
  19. 19 Template injection vulnerabilities in GitHub Actions workflows Low
  20. 20 Unpinned external GitHub CI/CD action versions Low
  21. 21 Potential privilege escalation due to insecure Dockerfile configurations Low
  22. 22 GitHub Actions role can modify KMS key policies, bypassing attestation requirements High
  23. 23 HTTP rate limiter configured but never invoked in request handlers Low
  24. 24 Prover proxy lacks CID validation, message size limits, and connection limits Medium

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related