Szafir SDK Trusted Bad Signatures as Verified

The break is in trust, not just signature math. Szafir SDK can return a clean verification result even when it cannot prove the signer’s certificate is trusted, so applications that rely on that result may accept an identity they never actually validated. CERT Polska says this is CVE-2026-9058 in Szafir SDK, and it was fixed in version 463. The failure affects applications that embed or consume the SDK for signature verification or authentication, because a normal-looking "verified" result can mask an unresolved certificate chain and enable authentication bypass or user impersonation.

Part of the PlainSec briefing for 2026-05-25

Sources