CVE-2026-57826
Received Received - Intake

X.509 Certificate Chain Validation Bypass in openHiTLS

Vulnerability report for CVE-2026-57826, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-18

Assigner: MITRE

Description

An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verification, the basic constraints extension and CA flag processing of intermediate CAs are only verified for v3 certificates, and v1/v2 certificates are ignored.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-18
Generated
2026-08-19
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
openhilt openhilt From 0.2.0 (inc) to 0.3.2 (inc)
openhitls openhitls From 0.2.0 (inc) to 0.3.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in openHiTLS versions 0.2.0 through 0.3.2. It involves improper verification of X.509 certificate chains where the basic constraints extension and CA flag processing for intermediate certificates are only checked for v3 certificates. Older v1/v2 certificate versions are incorrectly ignored during validation.

Impact Analysis

This could allow attackers to bypass certificate validation by presenting maliciously crafted v1/v2 certificates in a chain. This might enable man-in-the-middle attacks or unauthorized access to systems relying on openHiTLS for secure communications.

Compliance Impact

This vulnerability could violate compliance requirements that mandate proper certificate validation for secure communications, such as GDPR's data protection measures or HIPAA's encryption standards. Failure to validate certificates properly may result in non-compliance.

Mitigation Strategies

Update openHiTLS to version 0.3.3 or later to address the X.509 certificate chain verification issue. Ensure all intermediate CA certificates use v3 format with proper basic constraints and CA flag settings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57826. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart