VendorsApacheshiro3.0.0
Vulnerabilities

Apache Software Foundation Shiro 3.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-49268
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
Published 2026-06-17 · Analyzed
9.1EPSS 0.008
CVE-2026-43827
Apache Shiro: Session fixation: new session is not created after login by default
Published 2026-05-25 · Analyzed
6.5EPSS 0.005
CVE-2026-43828
Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default
Published 2026-05-25 · Analyzed
6.5EPSS 0.003
CVE-2026-44598
Apache Shiro Jakarta EE module: Open redirect and SSRF (requires valid credentials)
Published 2026-05-25 · Analyzed
5.4EPSS 0.005
CVE-2026-48589
Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flow
Published 2026-05-25 · Analyzed
5.4EPSS 0.005