Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.apache.shiro/shiro-web
  4. ›
  5. CVE-2026-43828

CVE-2026-43828: Apache Shiro sends sensitive cookies in HTTPS session without 'Secure' attribute

May 26, 2026 (updated June 30, 2026)

Default configurations of Apache Shiro send sensitive cookies in HTTPS session without ‘Secure’ attribute.

This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.

Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.

In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without ‘secure’ attribute by default.

References

  • github.com/advisories/GHSA-c6r4-qjmw-cvj2
  • nvd.nist.gov/vuln/detail/CVE-2026-43828
  • shiro.apache.org/security-reports.html

Code Behaviors & Features

Detect and mitigate CVE-2026-43828 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.0.0-incubating before 2.2.0, all versions starting from 3.0.0-alpha-1 before 3.0.0-alpha-2

Fixed versions

  • 2.2.0
  • 3.0.0-alpha-2

Solution

Upgrade to versions 2.2.0, 3.0.0-alpha-2 or above.

Impact 7.4 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Source file

maven/org.apache.shiro/shiro-web/CVE-2026-43828.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 13 Jul 2026 12:19:35 +0000.