GoSeverity: HighStatus: Published

Verifier treats p7.Certificates[0] as the signer: a signature by any untrusted key is reported Valid + TrustedChain and attributed to a trusted third-party certificate

The verifier used the first certificate in the signature (p7.Certificates[0]) as the signer, so a signature made with any untrusted key could be reported as Valid with a trusted chain and attributed to a trusted third-party certificate. Fixed in v1.0.0-rc4 (PR #175).

Timeline

  1. Found
  2. Reported via private vulnerability report
  3. Advisory published
  4. Entry last updated

Machine-readable: JSON · Markdown · ID security/go/digitorus__pdfsign/2026-10-06-signer-certificate-confusion