GHSA-7pq2-fhx9-x464

Suggest an improvement
Source
https://github.com/advisories/GHSA-7pq2-fhx9-x464
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-7pq2-fhx9-x464/GHSA-7pq2-fhx9-x464.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7pq2-fhx9-x464
Aliases
  • CVE-2026-48589
Published
2026-05-26T13:30:50Z
Modified
2026-07-10T21:45:19.375278783Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • 0.0 (None) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:D/RE:X/U:Green CVSS Calculator
Summary
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login
Details

Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.

Database specific
{
    "nvd_published_at": "2026-05-25T21:16:35Z",
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-10T21:42:44Z",
    "cwe_ids": [
        "CWE-601"
    ]
}
References

Affected packages

Maven / org.apache.shiro:shiro-jakarta-ee

Package

Name
org.apache.shiro:shiro-jakarta-ee
View open source insights on deps.dev
Purl
pkg:maven/org.apache.shiro/shiro-jakarta-ee

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0-alpha
Fixed
2.2.1

Affected versions

2.*
2.0.0-alpha-1
2.0.0-alpha-2
2.0.0-alpha-3
2.0.0-alpha-4
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.2.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-7pq2-fhx9-x464/GHSA-7pq2-fhx9-x464.json"

Maven / org.apache.shiro:shiro-jakarta-ee

Package

Name
org.apache.shiro:shiro-jakarta-ee
View open source insights on deps.dev
Purl
pkg:maven/org.apache.shiro/shiro-jakarta-ee

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0-alpha-0
Fixed
3.0.0-alpha-2

Affected versions

3.*
3.0.0-alpha-1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-7pq2-fhx9-x464/GHSA-7pq2-fhx9-x464.json"