{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-108572", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-10-10T15:23:18.969Z", "datePublished": "2026-10-11T11:00:16.042Z", "dateUpdated": "2026-10-11T11:00:16.042Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-10-11T11:00:16.042Z" }, "title": "Casdoor Proxy Validation cas.go CasP3ProxyValidate server-side request forgery", "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-918", "lang": "en", "description": "Server-Side Request Forgery" } ] } ], "affected": [ { "vendor": "n/a", "product": "Casdoor", "versions": [ { "version": "3.164", "status": "affected" }, { "version": "4.0", "status": "affected" }, { "version": "4.1", "status": "affected" }, { "version": "4.2", "status": "affected" }, { "version": "4.3", "status": "affected" }, { "version": "4.4", "status": "affected" }, { "version": "4.5", "status": "affected" }, { "version": "4.6", "status": "affected" }, { "version": "4.7", "status": "affected" }, { "version": "4.8", "status": "affected" }, { "version": "4.9", "status": "affected" }, { "version": "4.10.0", "status": "affected" }, { "version": "4.11.0", "status": "unaffected" } ], "cpes": [ "cpe:2.3:a:casdoor:casdoor:*:*:*:*:*:*:*:*" ], "modules": [ "Proxy Validation" ] } ], "descriptions": [ { "lang": "en", "value": "A security vulnerability has been detected in Casdoor up to 3.164.0/4.10.0. Affected is the function CasP3ProxyValidate of the file controllers/cas.go of the component Proxy Validation. Such manipulation of the argument pgtUrl leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 4.11.0 is able to address this issue. The name of the patch is 03c6c9aaa2eda5b085ce128ce0d60b34094efbd9/ada08ecd10cbf158f593dee23a8bab63efecf995. It is advisable to upgrade the affected component." } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "baseScore": 5.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P", "baseSeverity": "MEDIUM" } }, { "cvssV3_1": { "version": "3.1", "baseScore": 4.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C", "baseSeverity": "MEDIUM" } }, { "cvssV3_0": { "version": "3.0", "baseScore": 4.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C", "baseSeverity": "MEDIUM" } }, { "cvssV2_0": { "version": "2.0", "baseScore": 4, "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C" } } ], "timeline": [ { "time": "2026-10-10T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed" }, { "time": "2026-10-10T02:00:00.000Z", "lang": "en", "value": "VulDB entry created" }, { "time": "2026-10-10T17:28:36.000Z", "lang": "en", "value": "VulDB entry last update" } ], "credits": [ { "lang": "en", "value": "pngyuo (VulDB User)", "type": "reporter" }, { "lang": "en", "value": "VulDB Vulnerability Moderation Team", "type": "coordinator" } ], "references": [ { "url": "https://vuldb.com/vuln/416229", "name": "VDB-416229 | Casdoor Proxy Validation cas.go CasP3ProxyValidate server-side request forgery", "tags": [ "vdb-entry", "technical-description" ] }, { "url": "https://vuldb.com/vuln/416229/cti", "name": "VDB-416229 | CTI Indicators (IOB, IOC, IOA)", "tags": [ "signature", "permissions-required" ] }, { "url": "https://vuldb.com/cve/CVE-2026-108572", "name": "CVE-2026-108572 | CVE Analysis and Report", "tags": [ "third-party-advisory" ] }, { "url": "https://vuldb.com/submit/954813", "name": "Submit #954813 | Casdoor <= v3.153.0 Server-Side Request Forgery", "tags": [ "third-party-advisory" ] }, { "url": "https://github.com/casdoor/casdoor/commit/03c6c9aaa2eda5b085ce128ce0d60b34094efbd9", "tags": [ "patch" ] }, { "url": "https://github.com/casdoor/casdoor/releases/tag/v4.11.0", "tags": [ "patch" ] }, { "url": "https://github.com/casdoor/casdoor/", "tags": [ "product" ] } ], "tags": [ "x_open-source" ], "x_generator": [ "VulDB PVTS v202610" ] } } }