PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108572 Casdoor CVE debrief

A security vulnerability has been detected in Casdoor up to 3.164.0/4.10.0. The function CasP3ProxyValidate of the file controllers/cas.go of the component Proxy Validation is affected, allowing for server-side request forgery through manipulation of the argument pgtUrl. The attack may be performed from remote. Upgrading to version 4.11.0 addresses this issue.

Vendor
Casdoor
Product
Casdoor
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for Casdoor instances, especially those with versions up to 4.10.0, should assess exposure and prioritize upgrading to version 4.11.0 or applying compensating controls to mitigate potential server-side request forgery attacks.

Why it matters

Defenders should prioritize verifying exposure of Casdoor instances, especially those with versions up to 4.10.0, and assess the feasibility of server-side request forgery attacks. Immediate action is required to upgrade to version 4.11.0 or apply compensating controls.

  • Potential server-side request forgery attacks
  • Exposure of Casdoor instances to remote attacks
  • Need for verification of instance exposure and vulnerability
  • Priority for upgrading to version 4.11.0 or applying compensating controls

Technical summary

The Casdoor Proxy Validation function CasP3ProxyValidate in the file controllers/cas.go is vulnerable to server-side request forgery due to improper validation of the pgtUrl argument. This allows remote attackers to perform SSRF attacks. Affected product deployments should be verified, and defenders should prioritize upgrading to version 4.11.0 or applying compensating controls to mitigate potential attacks. The vulnerability has been publicly disclosed, emphasizing the need for immediate action to secure Casdoor instances, especially those with versions up to 4.10.0.

Defensive priority

Defenders should prioritize verifying exposure of Casdoor instances, especially those with versions up to 4.10.0, and assess the feasibility of server-side request forgery attacks. Immediate action is required to upgrade to version 4.11.0 or apply compensating controls.

Recommended defensive actions

  • Verify exposure of Casdoor instances, especially those with versions up to 4.10.0
  • Assess the feasibility of server-side request forgery attacks
  • Upgrade to version 4.11.0 or apply compensating controls
  • Monitor for potential exploitation attempts
  • Review and apply vendor patch guidance
  • Conduct exposure review for affected systems
  • Implement compensating controls for exposed instances

Evidence notes

The CVE record and source item provide details on the vulnerability in Casdoor's CasP3ProxyValidate function, which allows for server-side request forgery. The exploit has been disclosed publicly, and upgrading to version 4.11.0 is advised.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108572 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108572

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108572 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108572

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Casdoor Proxy Validation cas.go CasP3ProxyValidate server-side request forgery

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108572.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/vuln/416229

    Supplemental source - vdb-entry, technical-description

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/vuln/416229/cti

    Supplemental source - signature, permissions-required

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/cve/CVE-2026-108572

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/submit/954813

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/casdoor/casdoor/commit/03c6c9aaa2eda5b085ce128ce0d60b34094efbd9

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/casdoor/casdoor/releases/tag/v4.11.0

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/casdoor/casdoor/

    Supplemental source - product

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.