Home

Description

Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlResponse() never reads this field, meaning that time bounds are computed by the library but silently discarded before the user session is issued.

PUBLISHED Reserved 2026-05-20 | Published 2026-05-28 | Updated 2026-06-02 | Assigner certcc

Problem types

CWE-613 Insufficient Session Expiration

Product status

Any version
affected

References

kb.cert.org/vuls/id/780781

cve.org (CVE-2026-9096)

nvd.nist.gov (CVE-2026-9096)

Download JSON