CRITICAL 9.8 Go

Casdoor does not validate the AudienceRestriction element in SAML assertions

GHSA-3w4h-g9f5-j84p · CVE-2026-9093 · GO-2026-5894

Published · Modified

Description

In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor.

Ready to move

Start Securing

Free, no credit card | First findings in minutes