CVE-2026-48589 Details
Description
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.
A vulnerability in the Apache Shiro Jakarta EE module allows for open redirection attacks. The issue arises from the module's use of the HTTP Referer header to determine redirect targets after user login. In versions 2.0-alpha through 2.2.0 and 3.0.0-alpha-1, the module fails to properly validate this client-controlled header, enabling attackers to manipulate redirect destinations in affected applications.
Users can upgrade to Apache Shiro version 2.2.1 or 3.0.0-alpha-2 or later. These versions address the vulnerability by validating the Referer header and restricting redirects to relative paths within the current application context.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/05/25/9 | CVE | Mailing ListThird Party Advisory |
| https://shiro.apache.org/security-reports.html#cve_2026_48589 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache shiro | >= 2.0.0, < 2.2.1 3.0.0 alpha1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | Initial Analysis | [email protected] |
| May 25, 2026 | CVE Modified | CVE |
| May 25, 2026 | New CVE Received | [email protected] |