Apache Shiro
Apache · 16 CVEs
Apache Shiro: Server-side POST request may be steered to an alternate host
Aug 31, 2026
Apache Shiro: Authentication bypass in Guice-Web integration
Jun 25, 2026
Apache Shiro: Remember-me cookie isn't checked for expiry on the server
Jun 25, 2026
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
Jun 17, 2026
Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flow
May 25, 2026
Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default
May 25, 2026
Apache Shiro: Session fixation: new session is not created after login by default
May 25, 2026
Apache Shiro: Brute force attack possible to determine valid user names
Feb 10, 2026
Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems
Feb 9, 2026
Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentic…
Jan 15, 2024
Apache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache S…
Dec 14, 2023
Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with API…
Jul 24, 2023
Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher
Oct 12, 2022
Authentication Bypass Vulnerability
Jun 28, 2022
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an auth…
Sep 17, 2021
shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass
Jun 22, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-58301 | Apache Shiro: Server-side POST request may be steered to an alternate host | MEDIUM | 0.47% | Aug 31, 2026 |
| CVE-2026-56091 | Apache Shiro: Authentication bypass in Guice-Web integration | HIGH | 0.67% | Jun 25, 2026 |
| CVE-2026-56130 | Apache Shiro: Remember-me cookie isn't checked for expiry on the server | LOW | 0.30% | Jun 25, 2026 |
| CVE-2026-49268 | Apache Shiro: LDAP DN Injection in DefaultLdapRealm | HIGH | 0.76% | Jun 17, 2026 |
| CVE-2026-48589 | Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flow | LOW | 0.45% | May 25, 2026 |
| CVE-2026-43828 | Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default | MEDIUM | 0.33% | May 25, 2026 |
| CVE-2026-43827 | Apache Shiro: Session fixation: new session is not created after login by default | MEDIUM | 0.53% | May 25, 2026 |
| CVE-2026-23901 | Apache Shiro: Brute force attack possible to determine valid user names | LOW | 0.22% | Feb 10, 2026 |
| CVE-2026-23903 | Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems | MEDIUM | 0.40% | Feb 9, 2026 |
| CVE-2023-46749 | Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with pat… | MEDIUM | 1.19% | Jan 15, 2024 |
| CVE-2023-46750 | Apache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro. | MEDIUM | 1.50% | Dec 14, 2023 |
| CVE-2023-34478 | Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route req… | CRITICAL | 2.07% | Jul 24, 2023 |
| CVE-2022-40664 | Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher | CRITICAL | 2.67% | Oct 12, 2022 |
| CVE-2022-32532 | Authentication Bypass Vulnerability | CRITICAL | 25.54% | Jun 28, 2022 |
| CVE-2021-41303 | Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass | CRITICAL | 76.66% | Sep 17, 2021 |
| CVE-2020-11989 | shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass | CRITICAL | 24.44% | Jun 22, 2020 |
Showing 1 to 16 of 16 CVEs