GHSA-fwgq-j9r9-qjgr

Suggest an improvement
Source
https://github.com/advisories/GHSA-fwgq-j9r9-qjgr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fwgq-j9r9-qjgr/GHSA-fwgq-j9r9-qjgr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fwgq-j9r9-qjgr
Aliases
Published
2026-05-28T18:30:32Z
Modified
2026-07-07T16:11:20Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Casdoor has an authentication bypass
Details

Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts the X.509 certificate directly from the incoming SAMLResponse instead of using the trusted pre-configured Identity Provider certificate, allowing an attacker to forge assertions signed with an attacker-controlled key.

Database specific
{
    "cwe_ids":  [
        "CWE-287"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-02T18:36:50Z",
    "nvd_published_at":  "2026-05-28T17:16:33Z",
    "severity":  "CRITICAL"
}
References

Affected packages

Go / github.com/casdoor/casdoor

Package

Name
github.com/casdoor/casdoor
View open source insights on deps.dev
Purl
pkg:golang/github.com/casdoor/casdoor

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.1000.1-0.20260321120606-239e8bd69487

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fwgq-j9r9-qjgr/GHSA-fwgq-j9r9-qjgr.json"