← Vulnerability feed

Vulnerability record · CVE-2021-41303 · published 17 September 2021

CVE-2021-41303: Apache Shiro with Spring Boot authentication bypass via crafted HTTP request

Apache · Shiro

Apache Shiro before 1.8.0, when used with Spring Boot, can be tricked by a specially crafted HTTP request into bypassing authentication. The flaw is rated CVSS 3.1 9.8 (critical) and affects a widely deployed Java security framework, so any exposed Shiro-protected endpoint is a candidate target. The record does not describe the exact request pattern or which Shiro/Spring Boot combinations are affected beyond the version boundary.

9.8 CVSS 3.1 Critical EPSS 77% · top 0.5% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required, plus an EPSS probability above 0.76, makes this a top remediation priority despite no KEV listing.

What it is

Apache Shiro before 1.8.0, when used with Spring Boot, can be tricked by a specially crafted HTTP request into bypassing authentication. The flaw is rated CVSS 3.1 9.8 (critical) and affects a widely deployed Java security framework, so any exposed Shiro-protected endpoint is a candidate target. The record does not describe the exact request pattern or which Shiro/Spring Boot combinations are affected beyond the version boundary.

Impact

An unauthenticated attacker can reach protected resources without valid credentials, gaining the access level of the bypassed authentication check. Given the CVSS vector (C:H/I:H/A:H), full compromise of confidentiality, integrity and availability of the affected application is possible.

Attack surface

Reachable over the network via HTTP against a Shiro-protected Spring Boot application; the vector shows no privileges required and no user interaction. No authentication is needed to attempt the bypass.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.767, 99.5th percentile), indicating elevated likelihood of exploitation activity. Reference tags are vendor advisory, third-party advisory and patch only, with no public exploit tag supplied.

What to do

  • Upgrade Apache Shiro to 1.8.0 or later, or apply the vendor patch referenced in the Oracle CPU July 2022 advisory for bundled products.
  • Inventory all Spring Boot applications using Shiro and confirm the Shiro version in use, including transitive dependencies.
  • Where immediate upgrade is not possible, restrict network exposure of Shiro-protected endpoints and add an upstream authentication layer.
  • Review Shiro filter chain configuration for paths that may be unintentionally excluded from authentication.
  • Monitor vendor advisories for NetApp and Oracle product updates that bundle the affected Shiro version.

Detection

  • Search application and dependency logs for Shiro versions below 1.8.0 in Spring Boot deployments.
  • Alert on HTTP requests to Shiro-protected paths that return success without a prior successful authentication event.
  • Correlate access logs for unusual request patterns or path variants hitting authenticated endpoints from unauthenticated sessions.
  • Monitor for anomalous access to administrative or sensitive endpoints shortly after deployment of Shiro-based services.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41303 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-1273Spring Data Commons property binder allows remote code executionSpring Data Commons fails to properly neutralize special elements in request parameters, allowing crafted input to be bound to object properties. Thi…KEVEPSS 97%analysed9.8CVE-2016-4437Apache Shiro hardcoded remember-me cipher key enables code executionApache Shiro before 1.2.5 uses a default cipher key for the "remember me" feature when no key is configured, allowing attackers to forge or decrypt r…KEVEPSS 93%analysed9.8CVE-2023-34478Apache shiro path traversal vulnerabilityApache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used togeth…EPSS 2.1%9.8CVE-2022-40664Apache shiro improper authentication vulnerabilityApache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.EPSS 2.7%9.8CVE-2022-32532Apache shiro incorrect authorization vulnerabilityApache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatch…EPSS 26%9.8CVE-2022-22978Vmware spring security incorrect authorization vulnerabilityIn spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be b…EPSS 12%9.8CVE-2020-17523Apache Shiro with Spring authentication bypass via crafted HTTP requestApache Shiro before 1.7.1, when used with Spring, can be made to bypass authentication by a specially crafted HTTP request. The flaw is an improper a…EPSS 86%analysed9.8CVE-2020-17510Apache shiro improper authentication vulnerabilityApache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.EPSS 8.2%

Source: NIST National Vulnerability Database (record CVE-2021-41303), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.