๐Ÿ” CVE Alert

CVE-2026-58301

UNKNOWN 0.0

Apache Shiro: Server-side POST request may be steered to an alternate host

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Apache Shiro versions 2.x through 3.0.0 only in deployments that use the Jakarta EE integration module. Mitigation: Upgrade to version 3.0.1 or later, which fixes the issue. + Alternatively, you can set the `org.apache.shiro.form-resubmit-host` (String) and `org.apache.shiro.form-resubmit-port` (Integer) system properties to restrict the host and port that Shiro will connect to when resubmitting a form.

CWE CWE-918
Vendor apache software foundation
Product apache shiro
Published Aug 31, 2026
Last Updated Aug 31, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache shiro

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache shiro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Shiro
2.0.0-alpha-0 โ‰ค 3.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread/g1g84ovof5fnonvc5o89wym2jzt77fww openwall.com: http://www.openwall.com/lists/oss-security/2026/08/30/2

Credits

[email protected] (Liyi), https://lzhou1110.github.io/ [email protected] (Ziyue), https://zyy0530.github.io/ [email protected] (Strick), https://str1ckl4nd.github.io/ [email protected] (Maurice), http://maurice.busystar.org/ [email protected] (Chenchen), https://7thparkk.github.io/ Lenny Primak <[email protected]> Andrea Cosentino