VYPR
Medium severity6.5NVD Advisory· Published May 25, 2026· Updated Jul 24, 2026

CVE-2026-43828

CVE-2026-43828

Description

Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute.

This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.

Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.

In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.shiro:shiro-webMaven
>= 1.0.0-incubating, < 2.2.02.2.0
org.apache.shiro:shiro-webMaven
>= 3.0.0-alpha-1, < 3.0.0-alpha-23.0.0-alpha-2

Affected products

4
  • Apache/Shiroinferred4 versions
    >=1.0,<=2.1.0+ 3 more
    • (no CPE)range: >=1.0,<=2.1.0
    • cpe:2.3:a:apache:shiro:*:*:*:*:*:*:*:*range: <2.1.1
    • cpe:2.3:a:apache:shiro:3.0.0:alpha1:*:*:*:*:*:*
    • (no CPE)range: 1.0 - 2.1.0, 3.0.0-alpha-1

Patches

Vulnerability mechanics

References

4

News mentions

1