Feed/CVE-2026-43828
CVE-2026-43828MEDIUMCVSS 0.0

Apache Shiro sends sensitive cookies in HTTPS session without 'Secure' attribute

Published May 26, 2026·Updated Jun 30, 2026

NVD Description

Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.

Affected Packages (1)

org.apache.shiro:shiro-webMAVEN
From 1.0.0-incubating
Fixed in 2.2.0

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free