HALCON Documentation

Release notes for HALCON 26.05.0.1 Progress

Hotfix for HALCON 26.05.0.0 Progress

On this page, you can read the release notes for MVTec HALCON 26.05.0.1 Progress, as released in September 2026, which is a Hotfix for HALCON 26.05.0.0 Progress. For general information like licensing or supported operating systems, see the release notes of HALCON 26.05.0.0 Progress.


Detailed Description of Changes in HALCON 26.05.0.1 Progress (Hotfix)

The changes in HALCON 26.05.0.1 Progress are described with respect to HALCON 26.05.0.0 Progress.

Security-Related Topics

The following issues are relevant in the context of cybersecurity:

  • The third-party library Apache Thrift has been updated to version 0.24.0 to provide a fix for CVE-2026-55971, CVE-2026-58662, CVE-2026-48145, CVE-2026-48586, CVE-2026-55969, and CVE-2026-55970. This library is used for the communication between HDevelop and HDevEngine during remote debugging. HALCON applications that do not use HDevEngine are unaffected.

    HDevEngine production applications that run without enabling the debug server are also unaffected. If the debug server was enabled, exploiting potential vulnerabilities required malicious third-party software to be able to open a socket connection to the host/port combination configured for remote debugging.

    Another path to exploiting potential vulnerabilities was to trick an HDevelop user into initiating a remote debugging connection to a malicious third-party server.

  • Internal security checks identified the security vulnerability CVE-2026-34445. The vulnerability concerns the ONNX Python interface, which is not being used. The CVE is not applicable to our product and does not affect HALCON.

  • HALCON now uses version 8.41a of the CodeMeter Runtime. This update fixes security vulnerabilities in CodeMeter Runtime.

  • The third-party library OpenSSL has been updated to version 3.5.8. This fixes the security vulnerabilities CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, CVE-28387, CVE-28388, CVE-28389, CVE-28390, CVE-31789, CVE-31790, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, and CVE-2026-75803.

  • Internal security checks identified the security vulnerability CVE-2026-63632. The vulnerability concerns a potential crash in the ONNX third-party library. Our analysis showed that this CVE is not applicable to our product and does not affect HALCON.

HDevelop

Miscellaneous
  • The third-party library Apache Thrift has been updated to version 0.24.0 to provide a fix for CVE-2026-55971, CVE-2026-58662, CVE-2026-48145, CVE-2026-48586, CVE-2026-55969, and CVE-2026-55970. This library is used for the communication between HDevelop and HDevEngine during remote debugging. HALCON applications that do not use HDevEngine are unaffected.

    HDevEngine production applications that run without enabling the debug server are also unaffected. If the debug server was enabled, exploiting potential vulnerabilities required malicious third-party software to be able to open a socket connection to the host/port combination configured for remote debugging.

    Another path to exploiting potential vulnerabilities was to trick an HDevelop user into initiating a remote debugging connection to a malicious third-party server.

HDevEngine

Bug Fixes

  • The third-party library Apache Thrift has been updated to version 0.24.0 to provide a fix for CVE-2026-55971, CVE-2026-58662, CVE-2026-48145, CVE-2026-48586, CVE-2026-55969, and CVE-2026-55970. This library is used for the communication between HDevelop and HDevEngine during remote debugging. HALCON applications that do not use HDevEngine are unaffected.

    HDevEngine production applications that run without enabling the debug server are also unaffected. If the debug server was enabled, exploiting potential vulnerabilities required malicious third-party software to be able to open a socket connection to the host/port combination configured for remote debugging.

    Another path to exploiting potential vulnerabilities was to trick an HDevelop user into initiating a remote debugging connection to a malicious third-party server.

Third-Party Libraries

  • HALCON now uses version 8.41a of the CodeMeter Runtime.

Follow this link to read about the changes of previous HALCON versions.

MVTec Software