Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Systems integrating libdigidocpp should update to version 4.2.1 or later. Users of DigiDoc applications should update to fixed versions provided by the vendor: DigiDoc4 - 4.8.2 or later, RIA DigiDoc Android - 2.7.2 or later, and RIA DigiDoc iOS - 2.8.1 or later. Signatures that were validated with the vulnerable software versions should be revalidated.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 10 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before 4.8.2; DigiDoc on Android: from 2.7.0 before 2.7.2; DigiDoc on iOS: from 2.8.0 before 2.8.1. | |
| Title | Signature validation vulnerability affecting DigiDoc applications | |
| Weaknesses | CWE-347 CWE-754 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-08-10T17:55:30.587Z
Reserved: 2026-07-02T15:47:36.965Z
Link: CVE-2026-59112
Updated: 2026-08-10T17:55:24.289Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-10T18:45:17Z