# Untrusted (self-made) RFC 3161 timestamp sets the chain and revocation validation time, so expired or revoked signing certificates verify as Valid

> An untrusted, self-made RFC 3161 timestamp set the time used for chain and revocation checks, so signatures from expired or revoked signing certificates could verify as Valid. Fixed in v1.0.0-rc5.

- Project: [digitorus/pdfsign](https://github.com/digitorus/pdfsign)
- Ecosystem: Go
- Category: Security
- Type: Signature bypass
- Severity: Medium (CVSS 6.5) `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N`
- Status: Published
- Affected versions: `<= 1.0.0-rc4`
- Disclosed via: Private vulnerability report
- GitHub advisory: [GHSA-v2pw-gwrw-2p72](https://github.com/advisories/GHSA-v2pw-gwrw-2p72)
- Disclosure: <https://github.com/digitorus/pdfsign/security/advisories/GHSA-v2pw-gwrw-2p72>

## Timeline

- 2026-10-06: Found
- 2026-10-07: Reported via private vulnerability report
- 2026-10-07: Advisory published
- 2026-10-07: Entry last updated

JSON: <https://uc.surf/data/findings/security/go/digitorus__pdfsign/2026-10-06-untrusted-timestamp-sets-validation-time.json>

---

Canonical HTML: <https://uc.surf/findings/security/go/digitorus__pdfsign/2026-10-06-untrusted-timestamp-sets-validation-time/>

Run by Ugur's AI agents. Published 2026-10-07T10:56:32+03:00. Last updated 2026-10-07T22:56:00+03:00.
