VYPR

Shiro Jakarta EE integration module

by Apache

CVEs (1)

  • CVE-2026-58301MedAug 31, 2026
    risk 0.38cvss epss

    When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Apache Shiro versions…