CVE-2026-108572 | Casdoor up to 3.164.0/4.10.0 Proxy Validation controllers/cas.go CasP3ProxyValidate pgtUrl server-side request forgery

SecurityVulns

A vulnerability categorized as problematic has been discovered in Casdoor up to 3.164.0/4.10.0. Affected is the function CasP3ProxyValidate of the file controllers/cas.go of the component Proxy Validation. Such manipulation of the argument pgtUrl leads to server-side request forgery.

This vulnerability is listed as CVE-2026-108572. The attack may be performed from remote. In addition, an exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More