PatchSiren cyber security CVE debrief
CVE-2026-108572 Casdoor CVE debrief
A security vulnerability has been detected in Casdoor up to 3.164.0/4.10.0. The function CasP3ProxyValidate of the file controllers/cas.go of the component Proxy Validation is affected, allowing for server-side request forgery through manipulation of the argument pgtUrl. The attack may be performed from remote. Upgrading to version 4.11.0 addresses this issue.
- Vendor
- Casdoor
- Product
- Casdoor
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for Casdoor instances, especially those with versions up to 4.10.0, should assess exposure and prioritize upgrading to version 4.11.0 or applying compensating controls to mitigate potential server-side request forgery attacks.
Why it matters
Defenders should prioritize verifying exposure of Casdoor instances, especially those with versions up to 4.10.0, and assess the feasibility of server-side request forgery attacks. Immediate action is required to upgrade to version 4.11.0 or apply compensating controls.
- Potential server-side request forgery attacks
- Exposure of Casdoor instances to remote attacks
- Need for verification of instance exposure and vulnerability
- Priority for upgrading to version 4.11.0 or applying compensating controls
Technical summary
The Casdoor Proxy Validation function CasP3ProxyValidate in the file controllers/cas.go is vulnerable to server-side request forgery due to improper validation of the pgtUrl argument. This allows remote attackers to perform SSRF attacks. Affected product deployments should be verified, and defenders should prioritize upgrading to version 4.11.0 or applying compensating controls to mitigate potential attacks. The vulnerability has been publicly disclosed, emphasizing the need for immediate action to secure Casdoor instances, especially those with versions up to 4.10.0.
Defensive priority
Defenders should prioritize verifying exposure of Casdoor instances, especially those with versions up to 4.10.0, and assess the feasibility of server-side request forgery attacks. Immediate action is required to upgrade to version 4.11.0 or apply compensating controls.
Recommended defensive actions
- Verify exposure of Casdoor instances, especially those with versions up to 4.10.0
- Assess the feasibility of server-side request forgery attacks
- Upgrade to version 4.11.0 or apply compensating controls
- Monitor for potential exploitation attempts
- Review and apply vendor patch guidance
- Conduct exposure review for affected systems
- Implement compensating controls for exposed instances
Evidence notes
The CVE record and source item provide details on the vulnerability in Casdoor's CasP3ProxyValidate function, which allows for server-side request forgery. The exploit has been disclosed publicly, and upgrading to version 4.11.0 is advised.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108572 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108572
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108572 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108572
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Casdoor Proxy Validation cas.go CasP3ProxyValidate server-side request forgery
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108572.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/416229
Supplemental source - vdb-entry, technical-description
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/416229/cti
Supplemental source - signature, permissions-required
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-108572
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/954813
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/casdoor/casdoor/commit/03c6c9aaa2eda5b085ce128ce0d60b34094efbd9
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/casdoor/casdoor/releases/tag/v4.11.0
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/casdoor/casdoor/
Supplemental source - product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.