Vulnerabilities & Exploits · Credential Theft

Szafir SDK Trusted Bad Signatures as Verified

The break is in trust, not just signature math. Szafir SDK can return a clean verification result even when it cannot prove the signer’s certificate is trusted, so applications that rely on that result may accept an identity they never actually validated.

CERT Polska says this is CVE-2026-9058 in Szafir SDK, and it was fixed in version 463. The failure affects applications that embed or consume the SDK for signature verification or authentication, because a normal-looking "verified" result can mask an unresolved certificate chain and enable authentication bypass or user impersonation.

1 source · May 25

CVE-2026-9058

NVD KEV

Timeline

Sources

Part of the PlainSec briefing for 2026-05-25

Every edition of this story: Szafir SDK Trusted Bad Signatures as Verified

More from today