CVE Tools

Apache Shiro

17 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Apache Shiro, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Apache Shiro CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Apache Shiro CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-022
2026-030
2026-040
2026-053
2026-063
2026-070
2026-081
2026-090

Severity

How the 17 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical640%
  • High17%
  • Medium747%
  • Low17%

Latest CVEs

The 15 most recently published vulnerabilities affecting Apache Shiro.

  1. CVE-2026-58301Apache Shiro: Server-side POST request may be steered to an alternate host6.5
  2. CVE-2026-56091Apache Shiro: Authentication bypass in Guice-Web integration—
  3. CVE-2026-56130Apache Shiro: Remember-me cookie isn't checked for expiry on the server—
  4. CVE-2026-49268Apache Shiro: LDAP DN Injection in DefaultLdapRealm9.1
  5. CVE-2026-48589Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flow5.4
  6. CVE-2026-43828Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default6.5
  7. CVE-2026-43827Apache Shiro: Session fixation: new session is not created after login by default6.5
  8. CVE-2026-23901Apache Shiro: Brute force attack possible to determine valid user names2.5
  9. CVE-2026-23903Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems5.3
  10. CVE-2023-46749Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting 6.5
  11. CVE-2023-46750Apache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro.6.1
  12. CVE-2023-34478Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests.9.8
  13. CVE-2023-22602Apache Shiro before 1.11.0, when used with Spring Boot 2.6+, may allow authentication bypass through a specially crafted HTTP request7.5
  14. CVE-2022-40664Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher9.8
  15. CVE-2022-32532Authentication Bypass Vulnerability9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store