cbcvebase.

Apache Shiro vulnerabilities

23 known vulnerabilities affecting apache/shiro.

Total CVEs
23
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL9HIGH5MEDIUM8LOW1

Vulnerabilities

Page 2 of 2
CVE-2026-48589P4MEDIUMCVSS 5.4≥ 2.0.0, < 2.2.1v3.0.0-alpha12026-05-25
CVE-2026-48589 [MEDIUM] CWE-601 CVE-2026-48589: Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect aft Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.
nvd
CVE-2023-46750P4MEDIUMCVSS 6.1fixed in 1.13.0v2.0.02023-12-14
CVE-2023-46750 [MEDIUM] CWE-601 CVE-2023-46750: URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
nvd
CVE-2026-23901P4LOWCVSS 2.5fixed in 2.0.72026-02-10
CVE-2026-23901 [LOW] CWE-208 CVE-2026-23901: Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7. Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue. Prior to Shiro 2.0.7, code paths for non-existent vs. existing users are different enough, that a brute-force attack may be able to tell, by timing
nvd
Apache Shiro vulnerabilities | cvebase