Apache Shiro

6 known vulnerabilities in Apache Shiro, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-58301 CVSS 5.9 medium When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server…
  • CVE-2026-56130 CVSS 2.0 low "Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie and reuse it…
  • CVE-2026-49268 CVSS 8.8 high A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class…
  • CVE-2026-43828 CVSS 5.9 medium Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro…
  • CVE-2026-23901 CVSS 1.0 low Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7. Users are…
  • CVE-2026-23903 CVSS 5.3 medium Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are…