30
CVE-2026-73191: Apache Syncope: CAS service URL injection via Forwarded HTTP headers
Apache Syncope SRA CVE-2026-73191 enables CAS service URL injection via Forwarded HTTP headers.
Apache Syncope disclosed CVE-2026-73191, a moderate-rated open redirect vulnerability in the Syncope SRA. When the SRA is configured for CAS authentication, the target Apereo CAS service URL can be manipulated through Forwarded HTTP headers, redirecting users to an untrusted site. The flaw affects syncope-sra in versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Users should upgrade to fixed releases.
18
30
30
55
42
30
30
55
42
55
30
30
55
30
55
55
30
55
60
47
60
30
60
55
60
60
30
30
30
55
47
55
55
55
60
42
55
35
42