Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p8c7-hjc4-gwf8 | Casdoor vulnerable to SSRF via crafted Webhook URL |
Thu, 09 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:casbin:casdoor:2.356.0:*:*:*:*:*:*:* |
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Casbin
Casbin casdoor |
|
| Vendors & Products |
Casbin
Casbin casdoor |
Fri, 03 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL Handler. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Casdoor Webhook URL server-side request forgery | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-03T20:02:50.404Z
Reserved: 2026-04-03T07:26:01.452Z
Link: CVE-2026-5469
Updated: 2026-04-03T20:02:45.646Z
Status : Analyzed
Published: 2026-04-03T15:16:06.420
Modified: 2026-04-09T00:14:07.627
Link: CVE-2026-5469
No data.
OpenCVE Enrichment
Updated: 2026-04-09T08:29:15Z
Github GHSA