VYPR
Medium severity5.4NVD Advisory· Published May 25, 2026· Updated Jul 24, 2026

CVE-2026-48589

CVE-2026-48589

Description

Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.shiro:shiro-jakarta-eeMaven
>= 2.0-alpha, < 2.2.12.2.1
org.apache.shiro:shiro-jakarta-eeMaven
>= 3.0.0-alpha-0, < 3.0.0-alpha-23.0.0-alpha-2

Affected products

5
  • Apache/Shiroinferred4 versions
    >=2.0-alpha,<=2.2.0+ 3 more
    • (no CPE)range: >=2.0-alpha,<=2.2.0
    • cpe:2.3:a:apache:shiro:*:*:*:*:*:*:*:*range: >=2.0.0,<2.2.1
    • cpe:2.3:a:apache:shiro:3.0.0:alpha1:*:*:*:*:*:*
    • (no CPE)range: 2.0-alpha to 2.2.0, 3.0.0-alpha-1
  • Range: 2.0-alpha to 2.2.0, 3.0.0-alpha-1

Patches

Vulnerability mechanics

References

4

News mentions

1