The changes in HALCON 24.11.3.2 Progress-Steady are described with respect to HALCON 24.11.3.0 Steady.
The following issues are relevant in the context of cybersecurity:
Internal security checks identified the security vulnerabilities CVE-2024-0102, CVE-2024-0072, CVE-2023-25523, CVE-2024-0076 (third-party CUDA SDK, cublas). The vulnerabilities concern the tools nvdisasm and cuobjdump, which are shipped alongside the CUDA SDK. HALCON neither ships nor uses these binaries. Exploitation in the context of HALCON is therefore not possible, and the CVEs are not applicable for our product.
Internal security checks identified the security vulnerability CVE-2026-44512. The vulnerability concerns an indefinite denial of service, which can be caused by a malicious or faulty ONNX network. This situation cannot occur in HALCON. Therefore, exploitation in the context of HALCON is not possible, and the CVE is not applicable to our product.
The third-party library Apache Thrift has been updated to version 0.24.0 to provide a fix for CVE-2026-55971, CVE-2026-58662, CVE-2026-48145, CVE-2026-48586, CVE-2026-55969, and CVE-2026-55970. This library is used for the communication between HDevelop and HDevEngine during remote debugging. HALCON applications that do not use HDevEngine are unaffected.
HDevEngine production applications that run without enabling the debug server are also unaffected. If the debug server was enabled, exploiting potential vulnerabilities required malicious third-party software to be able to open a socket connection to the host/port combination configured for remote debugging.
Another path to exploiting potential vulnerabilities was to trick an HDevelop user into initiating a remote debugging connection to a malicious third-party server.
Internal security checks identified the security vulnerability CVE-2026-34445. The vulnerability concerns the ONNX Python interface, which is not being used. The CVE is not applicable to our product and does not affect HALCON.
HALCON now uses version 8.41a of the CodeMeter Runtime. This update fixes security vulnerabilities in CodeMeter Runtime.
The third-party library OpenSSL has been updated to version 3.5.8. This fixes the security vulnerabilities CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, CVE-28387, CVE-28388, CVE-28389, CVE-28390, CVE-31789, CVE-31790, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, and CVE-2026-75803.
Internal security checks identified the security vulnerability CVE-2026-63632. The vulnerability concerns a potential crash in the ONNX third-party library. Our analysis showed that this CVE is not applicable to our product and does not affect HALCON.
The third-party library Apache Thrift has been updated to version 0.24.0 to provide a fix for CVE-2026-55971, CVE-2026-58662, CVE-2026-48145, CVE-2026-48586, CVE-2026-55969, and CVE-2026-55970. This library is used for the communication between HDevelop and HDevEngine during remote debugging. HALCON applications that do not use HDevEngine are unaffected.
HDevEngine production applications that run without enabling the debug server are also unaffected. If the debug server was enabled, exploiting potential vulnerabilities required malicious third-party software to be able to open a socket connection to the host/port combination configured for remote debugging.
Another path to exploiting potential vulnerabilities was to trick an HDevelop user into initiating a remote debugging connection to a malicious third-party server.
The third-party library Apache Thrift has been updated to version 0.24.0 to provide a fix for CVE-2026-55971, CVE-2026-58662, CVE-2026-48145, CVE-2026-48586, CVE-2026-55969, and CVE-2026-55970. This library is used for the communication between HDevelop and HDevEngine during remote debugging. HALCON applications that do not use HDevEngine are unaffected.
HDevEngine production applications that run without enabling the debug server are also unaffected. If the debug server was enabled, exploiting potential vulnerabilities required malicious third-party software to be able to open a socket connection to the host/port combination configured for remote debugging.
Another path to exploiting potential vulnerabilities was to trick an HDevelop user into initiating a remote debugging connection to a malicious third-party server.
HALCON now uses version 8.41a of the CodeMeter Runtime.
Follow this link to read about the changes of previous HALCON versions.