{"schema_version": "1.6.1", "id": "CVE-2026-73191", "summary": "CAS service URL injection via Forwarded HTTP headers", "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope.\n\n\n\n\n\nWhen the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-supplied forwarded HTTP headers.\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.\n\nUsers are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "3.0.0-M0"}, {"last_affected": "3.0.0-M0"}]}, {"type": "SEMVER", "events": [{"introduced": "4.0.0-M0"}, {"last_affected": "4.0.0-M0"}]}, {"type": "SEMVER", "events": [{"introduced": "4.1.0-M0"}, {"last_affected": "4.1.0-M0"}]}]}], "references": [{"type": "WEB", "url": "https://lists.apache.org/thread/vx9bons1znhdkdpsxwjpy6qqqjc8xqtk"}]}