CVE-2026-43828 Details
Description
Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.
A vulnerability exists in default configurations of Apache Shiro, where sensitive cookies are sent over HTTPS without the 'Secure' attribute. This issue affects versions 1.0 to 2.1.0, as well as 3.0.0-alpha-1. In these versions, the Shiro-native session manager and the Remember-Me manager transmit JSESSIONID and rememberMe cookies without the 'Secure' attribute by default.
Users are advised to upgrade to Apache Shiro version 2.1.1 or 3.0.0-alpha-2 or later, both of which address this vulnerability by including the 'Secure' attribute in cookies. Instructions for upgrading can be found in the Apache Shiro documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/05/25/7 | CVE | Mailing ListThird Party Advisory |
| https://shiro.apache.org/security-reports.html#cve_2026_43828 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-614 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache shiro | < 2.1.1 3.0.0 alpha1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | Initial Analysis | [email protected] |
| May 25, 2026 | CVE Modified | CVE |
| May 25, 2026 | New CVE Received | [email protected] |