CVE-2026-59112 PUBLISHED

Signature validation vulnerability affecting DigiDoc applications

Assigner: ENISA
Reserved: 02.07.2026 Published: 10.08.2026 Updated: 10.08.2026

Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before 4.8.2; DigiDoc on Android: from 2.7.0 before 2.7.2; DigiDoc on iOS: from 2.8.0 before 2.8.1.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 4.4

Product Status

Vendor Estonian Information System Authority (RIA)
Product libdigidocpp
Versions Default: unaffected
  • affected from 4.1.0 to 4.2.1 (excl.)
Vendor Estonian Information System Authority (RIA)
Product DigiDoc4
Versions Default: unaffected
  • affected from 4.7.0 to 4.8.2 (excl.)
Vendor Estonian Information System Authority (RIA)
Product DigiDoc
Versions Default: unaffected
  • affected from 2.7.0 to 2.7.2 (excl.)
Vendor Estonian Information System Authority (RIA)
Product DigiDoc
Versions Default: unaffected
  • affected from 2.8.0 to 2.8.1 (excl.)

Solutions

Systems integrating libdigidocpp should update to version 4.2.1 or later.  Users of DigiDoc applications should update to fixed versions provided by the vendor:  DigiDoc4 - 4.8.2 or later, RIA DigiDoc Android - 2.7.2 or later, and RIA DigiDoc iOS - 2.8.1 or later.  Signatures that were validated with the vulnerable software versions should be revalidated.

Credits

  • Burak Can Kus & Aleksander Kamenik (Cybernetica) finder

References

Problem Types

  • CWE-347 Improper verification of cryptographic signature CWE
  • CWE-754: Improper Check for Unusual or Exceptional Conditions CWE