CVE-2026-57826
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.8epss 0.2%
exploitation probability
0.2%top 88% of all CVEs
observed exploitation
nono source reports it
An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verification, the basic constraints extension and CA flag processing of intermediate CAs are only verified for v3 certificates, and v1/v2 certificates are ignored.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
n/a · n/aReferences
https://gitcode.com/openHiTLS/openhitls/pull/1399https://gitcode.com/openHiTLS/openhitls/pull/1657https://github.com/openHiTLS/openHiTLS/commit/2d3b221d113b452bc197012b185978b8314ee8a4https://github.com/openHiTLS/openHiTLS/commit/4355cdf5b043d5b9ef698f8f57860f77f8e92561https://github.com/openHiTLS/openHiTLS/compare/openhitls-0.3.2...openhitls-0.3.3https://www.openhitls.net/zh/support/HTLS-2026-001.html