← Vulnerability feed

Vulnerability record · CVE-2026-58301 · published 31 August 2026

CVE-2026-58301: Apache shiro server-side request forgery (ssrf) vulnerability

Apache · Shiro

When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Apache Shiro versions 2.x through 3.0.0 only in deployments that use the Jakarta EE integration module. Mitigation: Upgrade to version 3.0.1 or later, which fixes the issue. + Alternatively, you can set the `org.apache.shiro.form-resubmit-host` (String) and `org.apache.shiro.form-resubmit-port` (Integer) system properties to restrict the host and port that Shiro will connect to when resubmitting a form.

5.9 CVSS 4.0 Medium EPSS 0.47% · top 61.8% CWE-918 · Server-side request forgery (SSRF)
5.9CVSS 4.0 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
1 Sep 2026Last modified by NVD

Description

When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Apache Shiro versions 2.x through 3.0.0 only in deployments that use the Jakarta EE integration module. Mitigation: Upgrade to version 3.0.1 or later, which fixes the issue. + Alternatively, you can set the `org.apache.shiro.form-resubmit-host` (String) and `org.apache.shiro.form-resubmit-port` (Integer) system properties to restrict the host and port that Shiro will connect to when resubmitting a form.

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-58301 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4437Apache Shiro hardcoded remember-me cipher key enables code executionApache Shiro before 1.2.5 uses a default cipher key for the "remember me" feature when no key is configured, allowing attackers to forge or decrypt r…KEVEPSS 93%analysed9.8CVE-2023-34478Apache shiro path traversal vulnerabilityApache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used togeth…EPSS 2.1%9.8CVE-2022-40664Apache shiro improper authentication vulnerabilityApache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.EPSS 2.7%9.8CVE-2022-32532Apache shiro incorrect authorization vulnerabilityApache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatch…EPSS 26%9.8CVE-2021-41303Apache Shiro with Spring Boot authentication bypass via crafted HTTP requestApache Shiro before 1.8.0, when used with Spring Boot, can be tricked by a specially crafted HTTP request into bypassing authentication. The flaw is …EPSS 77%analysed9.8CVE-2020-17523Apache Shiro with Spring authentication bypass via crafted HTTP requestApache Shiro before 1.7.1, when used with Spring, can be made to bypass authentication by a specially crafted HTTP request. The flaw is an improper a…EPSS 86%analysed9.8CVE-2020-17510Apache shiro improper authentication vulnerabilityApache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.EPSS 8.2%9.8CVE-2020-11989Apache shiro vulnerabilityApache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.EPSS 24%

Source: NIST National Vulnerability Database (record CVE-2026-58301), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.