Repository navigation
Security: digitorus/pdfsign
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Crafted /ByteRange with a negative length panics the fluent Verify().Valid() API (unrecovered makeslice panic, DoS)GHSA-c8v6-r46j-hm35 published
Oct 7, 2026 by vanbroupModerate -
Untrusted (self-made) RFC 3161 timestamp sets the chain and revocation validation time, so expired or revoked signing certificates verify as ValidGHSA-v2pw-gwrw-2p72 published
Oct 7, 2026 by vanbroupModerate -
Verifier treats p7.Certificates[0] as the signer: a signature by any untrusted key is reported Valid + TrustedChain and attributed to a trusted third-party certificateGHSA-2wq3-cx7v-37f3 published
Oct 7, 2026 by vanbroupHigh
Learn more about advisories related to digitorus/pdfsign in the GitHub Advisory Database