CVE-2026-57826
Received
Received - Intake
X.509 Certificate Chain Validation Bypass in openHiTLS
Vulnerability report for CVE-2026-57826, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-18
Last updated on: 2026-08-18
Assigner: MITRE
Description
Description
An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verification, the basic constraints extension and CA flag processing of intermediate CAs are only verified for v3 certificates, and v1/v2 certificates are ignored.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| openhilt | openhilt | From 0.2.0 (inc) to 0.3.2 (inc) |
| openhitls | openhitls | From 0.2.0 (inc) to 0.3.2 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |