📦 Shiro

by Apache

🔍 What is Shiro?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-34478

CRITICAL CVSS 9.8 Jul 24, 2023

This CVE describes an authentication bypass vulnerability in Apache Shiro that allows attackers to bypass security controls through path traversal techniques. It affects Apache Shiro versions before 1...

CVE-2021-41303

CRITICAL CVSS 9.8 Sep 17, 2021

CVE-2021-41303 is an authentication bypass vulnerability in Apache Shiro when used with Spring Boot. A specially crafted HTTP request can allow attackers to bypass authentication mechanisms and gain u...

CVE-2020-17523

CRITICAL CVSS 9.8 Feb 3, 2021

CVE-2020-17523 is an authentication bypass vulnerability in Apache Shiro when used with Spring. Attackers can craft HTTP requests to bypass authentication mechanisms and gain unauthorized access to pr...

CVE-2020-17510

CRITICAL CVSS 9.8 Nov 5, 2020

CVE-2020-17510 is an authentication bypass vulnerability in Apache Shiro when used with Spring. A specially crafted HTTP request can bypass authentication mechanisms, allowing unauthorized access to p...

CVE-2026-23903

MEDIUM CVSS 5.3 Feb 9, 2026

This CVE describes an authentication bypass vulnerability in Apache Shiro where attackers can access protected static files by changing the case of filenames in requests. It affects Apache Shiro versi...

CVE-2026-23901

LOW CVSS 2.5 Feb 10, 2026

This CVE describes an observable timing discrepancy vulnerability in Apache Shiro authentication. Attackers can use timing differences to distinguish between non-existent users and incorrect passwords...