CVE Tools

Shiro

25 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Shiro, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Shiro CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Shiro CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-022
2026-030
2026-040
2026-054
2026-061
2026-070
2026-081
2026-090

Severity

How the 25 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1040%
  • High520%
  • Medium936%
  • Low14%

Latest CVEs

The 15 most recently published vulnerabilities affecting Shiro.

  1. CVE-2026-58301Apache Shiro: Server-side POST request may be steered to an alternate host6.5
  2. CVE-2026-49268Apache Shiro: LDAP DN Injection in DefaultLdapRealm9.1
  3. CVE-2026-48589Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flow5.4
  4. CVE-2026-44598Apache Shiro Jakarta EE module: Open redirect and SSRF (requires valid credentials)5.4
  5. CVE-2026-43828Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default6.5
  6. CVE-2026-43827Apache Shiro: Session fixation: new session is not created after login by default6.5
  7. CVE-2026-23901Apache Shiro: Brute force attack possible to determine valid user names2.5
  8. CVE-2026-23903Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems5.3
  9. CVE-2023-46749Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting 6.5
  10. CVE-2023-46750Apache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro.6.1
  11. CVE-2023-34478Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests.9.8
  12. CVE-2023-22602Apache Shiro before 1.11.0, when used with Spring Boot 2.6+, may allow authentication bypass through a specially crafted HTTP request7.5
  13. CVE-2022-40664Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher9.8
  14. CVE-2022-32532Authentication Bypass Vulnerability9.8
  15. CVE-2021-41303Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store