Medium severity5.4NVD Advisory· Published May 25, 2026· Updated Jul 24, 2026
CVE-2026-48589
CVE-2026-48589
Description
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.shiro:shiro-jakarta-eeMaven | >= 2.0-alpha, < 2.2.1 | 2.2.1 |
org.apache.shiro:shiro-jakarta-eeMaven | >= 3.0.0-alpha-0, < 3.0.0-alpha-2 | 3.0.0-alpha-2 |
Affected products
5- Range: 2.0-alpha to 2.2.0, 3.0.0-alpha-1
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2026/05/25/9nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-7pq2-fhx9-x464ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-48589ghsaADVISORY
- shiro.apache.org/security-reports.htmlnvdVendor AdvisoryWEB
News mentions
1- Apache Ships 12 Patches Across 7 Projects: Shiro, Airflow, Syncope Lead the BatchVypr Intelligence · May 28, 2026