Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/casdoor/casdoor
  4. ›
  5. CVE-2026-9096

CVE-2026-9096: Casdoor doesn't enforce SAML assertion time bounds

May 28, 2026 (updated July 2, 2026)

Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlResponse() never reads this field, meaning that time bounds are computed by the library but silently discarded before the user session is issued.

References

  • github.com/advisories/GHSA-rgq2-93gj-ffxg
  • kb.cert.org/vuls/id/780781
  • nvd.nist.gov/vuln/detail/CVE-2026-9096

Code Behaviors & Features

Detect and mitigate CVE-2026-9096 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 1.1000.1-0.20260321120606-239e8bd69487

Solution

Unfortunately, there is no solution available yet.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-613: Insufficient Session Expiration

Source file

go/github.com/casdoor/casdoor/CVE-2026-9096.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 16 Jul 2026 00:18:27 +0000.