Junglewise Threat Intelligence

CVE-2026-59112: Estonian RIA libdigidocpp cryptographic signature verification bypass

CVE-2026-59112 · Severity: info · Published 2026-08-10

Executive brief

Estonian Information System Authority's digital signature and authentication libraries (libdigidocpp, DigiDoc4, DigiDoc mobile apps) contain flaws in cryptographic signature verification and exception handling. An attacker could potentially forge or bypass validation of digital signatures, undermining the integrity of electronically signed documents and potentially compromising digital identity authentication used for e-government services.

Technical details

The vulnerability involves two related issues: improper verification of cryptographic signatures and inadequate handling of unusual or exceptional conditions during signature processing. The root cause appears to be insufficient exception handling in libdigidocpp, where processing exceptions are not properly caught and validated, allowing malformed or invalid signatures to bypass validation checks. The affected components include libdigidocpp (the core cryptographic library), DigiDoc4 (desktop application), and DigiDoc on Android and iOS (mobile applications). Fixes have been merged into the codebase and patched versions are available (libdigidocpp 4.2.1+, DigiDoc4 4.8.2+, DigiDoc Android 2.7.2+, DigiDoc iOS 2.8.1+). The vulnerability is network-reachable and does not require prior authentication, as it affects signature validation at the application layer.

Affected products

  • Estonian Information System Authority libdigidocpp 4.1.0 to 4.2.0
  • Estonian Information System Authority DigiDoc4 4.7.0 to 4.8.1
  • Estonian Information System Authority DigiDoc Android 2.7.0 to 2.7.1
  • Estonian Information System Authority DigiDoc iOS 2.8.0

Timeline

  • 2026-08-10: disclosed: CVE-2026-59112 published on NVD
  • 2025-08-22: patched: Fix merged into libdigidocpp master branch
  • 2025-08-20: other: RIA released ID-software version 25.8 with improved signature validation

References

Related threats