CVE-2026-57826
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verification, the basic constraints extension and CA flag processing of intermediate CAs are only verified for v3 certificates, and v1/v2 certificates are ignored.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
- https://github.com/openHiTLS/openHiTLS/compare/openhitls-0.3.2…openhitls-0.3.3
- https://www.openhitls.net/zh/support/HTLS-2026-001.html
- https://github.com/openHiTLS/openHiTLS/commit/4355cdf5b043d5b9ef698f8f57860f77f8e92561
- https://github.com/openHiTLS/openHiTLS/commit/2d3b221d113b452bc197012b185978b8314ee8a4
- https://gitcode.com/openHiTLS/openhitls/pull/1399
- https://gitcode.com/openHiTLS/openhitls/pull/1657
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.