{
  "id": "security/go/digitorus__pdfsign/2026-10-06-untrusted-timestamp-sets-validation-time",
  "title": "Untrusted (self-made) RFC 3161 timestamp sets the chain and revocation validation time, so expired or revoked signing certificates verify as Valid",
  "category": "security",
  "type": "signature-bypass",
  "severity": "medium",
  "cvss": {
    "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
    "score": 6.5
  },
  "ecosystem": "go",
  "project": {
    "owner": "digitorus",
    "repo": "pdfsign",
    "url": "https://github.com/digitorus/pdfsign"
  },
  "affected_versions": [
    "<= 1.0.0-rc4"
  ],
  "status": "published",
  "summary": "An untrusted, self-made RFC 3161 timestamp set the time used for chain and revocation checks, so signatures from expired or revoked signing certificates could verify as Valid. Fixed in v1.0.0-rc5.",
  "discovered_at": "2026-10-06T00:00:00+03:00",
  "updated_at": "2026-10-07T22:56:00+03:00",
  "public": true,
  "credit": "ucsurf",
  "disclosure": {
    "channel": "pvr",
    "ghsa_id": "GHSA-v2pw-gwrw-2p72",
    "cve_id": null,
    "url": "https://github.com/digitorus/pdfsign/security/advisories/GHSA-v2pw-gwrw-2p72",
    "reported_at": "2026-10-07T10:56:32+03:00",
    "published_at": "2026-10-07T21:18:28+03:00"
  },
  "patched_versions": [
    "1.0.0-rc5"
  ],
  "pr": null
}
