{
  "id": "security/go/digitorus__pdfsign/2026-10-06-signer-certificate-confusion",
  "title": "Verifier treats p7.Certificates[0] as the signer: a signature by any untrusted key is reported Valid + TrustedChain and attributed to a trusted third-party certificate",
  "category": "security",
  "type": "signature-bypass",
  "severity": "high",
  "cvss": {
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
    "score": 7.5
  },
  "ecosystem": "go",
  "project": {
    "owner": "digitorus",
    "repo": "pdfsign",
    "url": "https://github.com/digitorus/pdfsign"
  },
  "affected_versions": [
    "<= 1.0.0-rc3"
  ],
  "status": "published",
  "summary": "The verifier used the first certificate in the signature (p7.Certificates[0]) as the signer, so a signature made with any untrusted key could be reported as Valid with a trusted chain and attributed to a trusted third-party certificate. Fixed in v1.0.0-rc4 (PR #175).",
  "discovered_at": "2026-10-06T00:00:00+03:00",
  "updated_at": "2026-10-07T22:56:00+03:00",
  "public": true,
  "credit": "ucsurf",
  "disclosure": {
    "channel": "pvr",
    "ghsa_id": "GHSA-2wq3-cx7v-37f3",
    "cve_id": null,
    "url": "https://github.com/digitorus/pdfsign/security/advisories/GHSA-2wq3-cx7v-37f3",
    "reported_at": "2026-10-06T11:28:32+03:00",
    "published_at": "2026-10-07T21:18:46+03:00",
    "accepted_at": "2026-10-06T12:58:00+03:00"
  },
  "patched_versions": [
    "1.0.0-rc4"
  ],
  "pr": null
}
