Sceawere

Vulnerability Detail

CVE-2026-108572UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SSRF in Casdoor Proxy Validation

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
4h ago
Vendor
n/a
Product
Casdoor
Attack Type
Server-Side Request Forgery
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in Casdoor up to 3.164.0/4.10.0. Affected is the function CasP3ProxyValidate of the file controllers/cas.go of the component Proxy Validation. Such manipulation of the argument pgtUrl leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 4.11.0 is able to address this issue. The name of the patch is 03c6c9aaa2eda5b085ce128ce0d60b34094efbd9/ada08ecd10cbf158f593dee23a8bab63efecf995. It is advisable to upgrade the affected component.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T11:17:00.370Z",
  "pubdate": "2026-10-11T11:17:00.370Z",
  "executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability has been identified in Casdoor versions up to 3.164.0 and 4.10.0.\nThe vulnerability resides within the Proxy Validation component, specifically affecting the CasP3ProxyValidate function located in controllers/cas.go.\nThis flaw permits a remote, unauthenticated attacker to manipulate the pgtUrl parameter, forcing the Casdoor server to initiate arbitrary HTTP requests to unintended destinations.\nSuccessful exploitation allows an attacker to bypass network access controls, interact with internal services unreachable from the public internet, or probe the internal network infrastructure.\nGiven the public disclosure of the exploit, the risk profile is considered high.\nImmediate remediation involves upgrading to version 4.11.0, which contains the necessary patch to sanitize inputs and prevent unauthorized request redirection.",
  "technicalDetails": "The vulnerability is a classic SSRF flaw originating from improper validation of user-supplied input within the Proxy Validation mechanism of Casdoor. The root cause is the insecure handling of the pgtUrl argument in the CasP3ProxyValidate function inside controllers/cas.go.\nThe application fails to perform sufficient whitelist or blacklist validation on the provided URL scheme and hostname. Consequently, when the function processes the request, it utilizes the user-controlled pgtUrl to perform a back-end HTTP request to the specified target.\nAttack flow: An unauthenticated remote attacker initiates a request to the affected endpoint, injecting a crafted URI into the pgtUrl parameter. The vulnerable application logic processes this parameter without verifying if the target destination is legitimate or intended. The server then acts as a proxy, executing a GET or POST request to the attacker-supplied destination. This allows the attacker to interact with internal resources, such as internal APIs, metadata services (e.g., cloud environment credentials), or sensitive local network services that were never intended to be exposed to the public.\nAffected components: The vulnerability is specifically localized to the Proxy Validation logic within controllers/cas.go. It impacts all versions of Casdoor up to 3.164.0 and 4.10.0.\nExploitation requirements: The attack does not require prior authentication or elevated privileges, making it accessible to any remote actor capable of reaching the vulnerable Casdoor instance. Because the server itself performs the malicious request, the attacker can bypass perimeter firewalls that would otherwise block direct access to the internal target resource.\nImpact: Beyond simple request redirection, the impact includes potential information disclosure of internal network topography, sensitive data exfiltration from internal services, and potential service disruption or internal service abuse. Post-exploitation, an attacker may use this capability as a pivot point for further network reconnaissance or lateral movement within the infrastructure hosting the Casdoor application.\nThe patch associated with this vulnerability (03c6c9aaa2eda5b085ce128ce0d60b34094efbd9/ada08ecd10cbf158f593dee23a8bab63efecf995) addresses the issue by implementing stricter validation logic, likely enforcing a whitelist for permitted protocols and hostnames, or by restricting requests to trusted internal or external endpoints."
}
CVE-2026-108572: SSRF in Casdoor Proxy Validation (MEDIUM Severity, CVSS: 4.3) | Sceawere