{"id":"CVE-2026-59112","details":"Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before 4.8.2; DigiDoc on Android: from 2.7.0 before 2.7.2; DigiDoc on iOS: from 2.8.0 before 2.8.1.","modified":"2026-09-03T08:07:07.388250Z","published":"2026-08-10T14:17:25.153Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"4.7.0"},{"fixed":"4.8.2"},{"introduced":"2.7.0"},{"fixed":"2.7.2"},{"introduced":"2.8.0"},{"fixed":"2.8.1"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"https://www.id.ee/en/article/ria-soovitab-kasutajatel-uuendada-id-tarkvara-eng/"},{"type":"FIX","url":"https://github.com/open-eid/libdigidocpp/pull/690"},{"type":"ARTICLE","url":"https://www.ria.ee/blogi/digidoc-rakendustes-esinenud-turvanorkus-mis-juhtus-ja-kuidas-see-parandati"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open-eid/libdigidocpp","events":[{"introduced":"e7bbc3030000136dd7d3a3ec821a8f47c1e814d4"},{"fixed":"d3be4658163de64dfd53d7f1a75a607b3b4941ed"}],"database_specific":{"extracted_events":[{"introduced":"4.1.0"},{"fixed":"4.2.1"}],"source":"DESCRIPTION"}}],"versions":["v4.2.0","v4.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59112.json","vanir_signatures_modified":"2026-09-03T08:07:07Z","vanir_signatures":[{"digest":{"function_hash":"332230419720299925772037175555635323748","length":2854},"id":"CVE-2026-59112-37bfff4d","signature_type":"Function","signature_version":"v1","source":"https://github.com/open-eid/libdigidocpp/commit/d3be4658163de64dfd53d7f1a75a607b3b4941ed","target":{"file":"src/SignatureXAdES_LT.cpp","function":"SignatureXAdES_LT::validate"},"deprecated":false},{"source":"https://github.com/open-eid/libdigidocpp/commit/d3be4658163de64dfd53d7f1a75a607b3b4941ed","target":{"file":"src/SignatureXAdES_LTA.cpp","function":"SignatureXAdES_LTA::validate"},"deprecated":false,"digest":{"length":777,"function_hash":"61817033134040619216336980561578315012"},"id":"CVE-2026-59112-3e97eb52","signature_type":"Function","signature_version":"v1"},{"digest":{"line_hashes":["174432059240807719511509665271045474816","120189340633842629588547634783890387258","231675631162022903727607268410955252926","29646744210869861824659573018519514954"],"threshold":0.9},"id":"CVE-2026-59112-57009617","signature_type":"Line","signature_version":"v1","source":"https://github.com/open-eid/libdigidocpp/commit/d3be4658163de64dfd53d7f1a75a607b3b4941ed","target":{"file":"src/SignatureXAdES_LT.cpp"},"deprecated":false},{"source":"https://github.com/open-eid/libdigidocpp/commit/d3be4658163de64dfd53d7f1a75a607b3b4941ed","target":{"file":"src/SignatureXAdES_B.cpp","function":"SignatureXAdES_B::validate"},"deprecated":false,"digest":{"function_hash":"40460027225072446988488056903714477420","length":4735},"id":"CVE-2026-59112-a84bfd97","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/open-eid/libdigidocpp/commit/d3be4658163de64dfd53d7f1a75a607b3b4941ed","target":{"file":"src/SignatureXAdES_LTA.cpp"},"deprecated":false,"digest":{"line_hashes":["41205052967299249860806274248166521375","337965608311638731389519978221719771974","231675631162022903727607268410955252926","29646744210869861824659573018519514954"],"threshold":0.9},"id":"CVE-2026-59112-c74f7e5a","signature_type":"Line","signature_version":"v1"},{"target":{"file":"src/SignatureXAdES_T.cpp","function":"SignatureXAdES_T::validate"},"deprecated":false,"digest":{"function_hash":"314436310575302677297720859238470524697","length":3270},"id":"CVE-2026-59112-c90e4035","signature_type":"Function","signature_version":"v1","source":"https://github.com/open-eid/libdigidocpp/commit/d3be4658163de64dfd53d7f1a75a607b3b4941ed"},{"digest":{"threshold":0.9,"line_hashes":["133764611298990166201157945954800979698","120189340633842629588547634783890387258","231675631162022903727607268410955252926","29646744210869861824659573018519514954"]},"id":"CVE-2026-59112-fcc0f361","signature_type":"Line","signature_version":"v1","source":"https://github.com/open-eid/libdigidocpp/commit/d3be4658163de64dfd53d7f1a75a607b3b4941ed","target":{"file":"src/SignatureXAdES_T.cpp"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}