epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45 discards the boolean return value of Signature.verify(). The method performs certificate chain validation, OCSP check, and signature algorithm setup, but never checks whether the signature actually matches. For any structurally valid signature, it returns true. This vulnerability is fixed in 1.2.1.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-295"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44900.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44900.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"181118184525831887307810226594547994740",
"71686158905792473797514938050563979926",
"220426661105732065751424757946103786951",
"217835864713610173097007328788152445091",
"271863141297825314928147573796093117875",
"219476708332884617218025522771184397972",
"270545454777956786985407730446358871363",
"148001014682448145396629012250166341123",
"114685946368072089166944777835336812171",
"101804884370391579187844878415863945962",
"290620666043658206325141165967195813421",
"113733595349261336119811680451020657124",
"242780960819741343164487702071292704996",
"187622935415389194453841136217522995461",
"51995103149806247417055846500732687400",
"253768069638543364593732898853672718891",
"321544711301458627350015494708065527455",
"335915038979836551863709027751354944456",
"105135349804760838859480469610730392589",
"102715412356406950219770955940244365114"
],
"threshold": 0.9
},
"id": "CVE-2026-44900-0340d8a5",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/oviva-ag/epa4all-client/commit/e13fa838c7b2c7e66f9abfffbe108a85f2f4d0c6",
"target": {
"file": "vau/vau-httpclient/src/main/java/com/oviva/telematik/vau/httpclient/internal/SignedPublicKeysTrustValidatorImpl.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "152320029170772371568148515103622094065",
"length": 717
},
"id": "CVE-2026-44900-299be349",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/oviva-ag/epa4all-client/commit/e13fa838c7b2c7e66f9abfffbe108a85f2f4d0c6",
"target": {
"file": "vau/vau-httpclient/src/main/java/com/oviva/telematik/vau/httpclient/internal/SignedPublicKeysTrustValidatorImpl.java",
"function": "isTrusted"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"128105541723180769108402405937591158225",
"244036373056257559619278424501304528004",
"83924046338240063547189581906308206165",
"192092695851175725203867735832647298327",
"101265061726185422164134040250765107134",
"124450592394235045677730040363130997696",
"249527586736346887202759455357152332951",
"336538503709471426103492731203160675703"
],
"threshold": 0.9
},
"id": "CVE-2026-44900-398b6eb9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/oviva-ag/epa4all-client/commit/e13fa838c7b2c7e66f9abfffbe108a85f2f4d0c6",
"target": {
"file": "vau/vau-httpclient/src/main/java/com/oviva/telematik/vau/httpclient/internal/SignedPublicKeysTrustValidatorFactory.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "154263762694756952047399939232652243851",
"length": 118
},
"id": "CVE-2026-44900-44e72aaf",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/oviva-ag/epa4all-client/commit/e13fa838c7b2c7e66f9abfffbe108a85f2f4d0c6",
"target": {
"file": "vau/vau-httpclient/src/main/java/com/oviva/telematik/vau/httpclient/internal/SignedPublicKeysTrustValidatorFactory.java",
"function": "create"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "68809148766778528062299133107425454022",
"length": 129
},
"id": "CVE-2026-44900-d9cfae7e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/oviva-ag/epa4all-client/commit/e13fa838c7b2c7e66f9abfffbe108a85f2f4d0c6",
"target": {
"file": "vau/vau-httpclient/src/main/java/com/oviva/telematik/vau/httpclient/internal/SignedPublicKeysTrustValidatorImpl.java",
"function": "SignedPublicKeysTrustValidatorImpl"
}
}
]
"2026-08-12T16:25:17Z"