CVE-2026-43828
published 2026-05-25CVE-2026-43828: Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0…
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.27%
19.4th percentile
Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute.
This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.
Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.
In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shiro | < 2.1.1 | 2.1.1 |
| apache | shiro | — | — |
| apache_software_foundation | apache_shiro | 1.0 – 2.1.0 | — |
| apache_software_foundation | apache_shiro | 3.0.0-alpha-0 – 3.0.0-alpha-1 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv4.05.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:L/U:Amber
cvelistv5v4.05.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/AU:Y/R:U/RE:L/U:Amber
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Shiro sends sensitive cookies in HTTPS session without 'Secure' attribute
ghsa·2026-05-26
CVE-2026-43828 [MEDIUM] CWE-614 Apache Shiro sends sensitive cookies in HTTPS session without 'Secure' attribute
Apache Shiro sends sensitive cookies in HTTPS session without 'Secure' attribute
Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute.
This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.
Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.
In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.
GHSA
GHSA-c6r4-qjmw-cvj2: Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute
ghsa_unreviewed·2026-05-26
CVE-2026-43828 [MEDIUM] CWE-614 GHSA-c6r4-qjmw-cvj2: Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute
Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute.
This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.
Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.
In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.
CVEList
Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default
cvelistv5·2026-05-25·CVSS 5.9
CVE-2026-43828 [MEDIUM] CWE-614 Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default
Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default
Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute.
This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.
Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.
In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.
Red Hat
apache-shiro: Apache Shiro: Information disclosure via insecure cookie handling
vendor_redhat·2026-05-25·CVSS 6.5
CVE-2026-43828 [MEDIUM] CWE-319 apache-shiro: Apache Shiro: Information disclosure via insecure cookie handling
apache-shiro: Apache Shiro: Information disclosure via insecure cookie handling
Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute.
This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.
Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.
In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.
A flaw was found in Apache Shiro. Default configurations of Apache Shiro send sensitive cookies, such as JSESSIONID and rememberMe, in HTTPS sessions without the 'Secure' attribute. This oversight could allow a remote attacker to intercept these cookies, potentially leading
No detection rules found.
No public exploits indexed.
2026-05-25
Published