HarborGuard / CVE
Back to search
HIGHCVE-2026-44900Published Modified CNA GitHub_M

CVE-2026-44900: epa4all-client: VAU Signature bypass

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45 discards the boolean return value of Signature.verify(). The method performs certificate chain validation, OCSP check, and signature algorithm setup, but never checks whether the signature actually matches. For any structurally valid signature, it returns true. This vulnerability is fixed in 1.2.1.

Metrics

CVSS v3.1
8.1
Severity
HIGH
Fixed in
Affected Products
2
Affected packages
  • oviva-ag / epa4all-client
    < 1.2.1
  • com.oviva.telematik / epa4all-client
    < 1.2.1
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N