org.apache.shiro:shiro-jakarta-ee
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.shiro:shiro-jakarta-eepage 1 of 1
- CVE-2026-44598MEDIUMCVSS 5.4EG 5.4✓ Fixed in 3.0.0-alpha-22026-05-25
vulnerable: 3.0.0-alpha-1
With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. This issue affects Apache Shiro from 2.0-alpha to 2.1.0, and 3.0.0-alpha-1, only when…
- CVE-2026-48589MEDIUMCVSS 5.4EG 5.4✓ Fixed in 3.0.0-alpha-22026-05-25
vulnerable: 3.0.0-alpha-1
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the r…
Check whether org.apache.shiro:shiro-jakarta-ee is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.shiro:shiro-jakarta-ee CVEs against the assets you own.
Start Free Scan →