CVE-2026-73191: Apache Syncope: CAS service URL injection via Forwarded HTTP headers
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope.
When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-supplied forwarded HTTP headers.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.0.8 - Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.1.3
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Apache Syncope deployments using the Syncope SRA with CAS authentication are exposed if they run affected releases: 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, or 4.1.0-M0 through 4.1.2.
What does an attacker need to exploit the vulnerability?
An attacker needs to be able to supply forwarded HTTP headers to the Syncope SRA. The vulnerable behavior occurs because the CAS service URL is calculated using those client-supplied headers without validation.
What versions remediate the issue?
Upgrade to Apache Syncope 4.0.8 or 4.1.3, which fix the issue.