CVE-2026-59112: Estonian Information System Authority Ria Digidoc
Medium severity, CVSS 4.4. EPSS: 0.1% chance of exploitation in the next 30 days.
Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before 4.8.2; DigiDoc on Android: from 2.7.0 before 2.7.2; DigiDoc on iOS: from 2.8.0 before 2.8.1.
Affected products
- Estonian Information System Authority Ria Digidoc: from 2.7.0, before 2.7.2 (fixed in 2.7.2); from 2.8.0, before 2.8.1 (fixed in 2.8.1)
- Estonian Information System Authority Ria DIGIDOC4: from 4.7.0, before 4.8.2 (fixed in 4.8.2)
- Estonian Information System Authority Ria Libdigidocpp: from 4.1.0, before 4.2.1 (fixed in 4.2.1)
Published 2026-08-10. Last modified 2026-09-01.