Apache Shiro
6 known vulnerabilities in Apache Shiro, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-58301 CVSS 5.9 medium When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server…
- CVE-2026-56130 CVSS 2.0 low "Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie and reuse it…
- CVE-2026-49268 CVSS 8.8 high A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class…
- CVE-2026-43828 CVSS 5.9 medium Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro…
- CVE-2026-23901 CVSS 1.0 low Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7. Users are…
- CVE-2026-23903 CVSS 5.3 medium Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are…