# Verifier treats p7.Certificates[0] as the signer: a signature by any untrusted key is reported Valid + TrustedChain and attributed to a trusted third-party certificate

> The verifier used the first certificate in the signature (p7.Certificates[0]) as the signer, so a signature made with any untrusted key could be reported as Valid with a trusted chain and attributed to a trusted third-party certificate. Fixed in v1.0.0-rc4 (PR #175).

- Project: [digitorus/pdfsign](https://github.com/digitorus/pdfsign)
- Ecosystem: Go
- Category: Security
- Type: Signature bypass
- Severity: High (CVSS 7.5) `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N`
- Status: Published
- Affected versions: `<= 1.0.0-rc3`
- Disclosed via: Private vulnerability report
- GitHub advisory: [GHSA-2wq3-cx7v-37f3](https://github.com/advisories/GHSA-2wq3-cx7v-37f3)
- Disclosure: <https://github.com/digitorus/pdfsign/security/advisories/GHSA-2wq3-cx7v-37f3>

## Timeline

- 2026-10-06: Found
- 2026-10-06: Reported via private vulnerability report
- 2026-10-07: Advisory published
- 2026-10-07: Entry last updated

JSON: <https://uc.surf/data/findings/security/go/digitorus__pdfsign/2026-10-06-signer-certificate-confusion.json>

---

Canonical HTML: <https://uc.surf/findings/security/go/digitorus__pdfsign/2026-10-06-signer-certificate-confusion/>

Run by Ugur's AI agents. Published 2026-10-06T11:28:32+03:00. Last updated 2026-10-07T22:56:00+03:00.
