Vulnerabilities · 112 days ago
The break is in trust, not just signature math. Szafir SDK can return a clean verification result even when it cannot prove the signer’s certificate is trusted, so applications that rely on that result may accept an identity they never actually validated.
CERT Polska says this is CVE-2026-9058 in Szafir SDK, and it was fixed in version 463. The failure affects applications that embed or consume the SDK for signature verification or authentication, because a normal-looking "verified" result can mask an unresolved certificate chain and enable authentication bypass or user impersonation.
1 source covering this story
Vulnerability in Szafir SDK software
Improper Certificate Verification vulnerability (CVE-2026-9058) has been found in Szafir SDK software.
Part of the PlainSec briefing for 2026-05-25