@niwinz check out https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11424 I just read it on the go, so I haven't checked if there are tests in buddy-sign to ensure the same doesn't happen