VYPR

Apache Shiro

by Apache Shiro

CVEs (1)

  • CVE-2026-43828MedMay 25, 2026
    risk 0.38cvss epss 0.00

    Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the…