When using smart card certificate filter you enter a comma separated list of attribute-value pairs in the issuer field. If one entry in the list is malformed the filter is not used and all you get in the log is "Malformed token [...]".
This was found when accidentally adding a trailing comma to the list:
> cn=Telia Test e-leg CA v2,c=SE,
I got this in the log:
> 2021-10-06T13:01:48: Malformed token ""
and all certificates on the smart card was shown in the certificate list. Tested with 4.13.0 client on Fedora 34.
Not sure what's the best way to handle an actual malformed entry. But this special case with an extra comma should probably be handled better?