Casdoor · Casdoor · CVE-2026-9096
**Name of the Vulnerable Software and Affected Versions**
Casdoor versions prior to 2.363.0
**Description**
Casdoor fails to enforce SAML assertion time bounds. The `gosaml2` library calculates time-validation results, such as `NotOnOrAfter` and `NotBefore`, and reports them in the `assertionInfo.WarningInfo` field. However, the `ParseSamlResponse()` function does not read this field, causing the time bounds to be discarded before a user session is issued.
**Recommendations**
Update to a version later than 2.362.0.