GHSA-c4qc-4q9p-m9q9

Suggest an improvement
Source
https://github.com/advisories/GHSA-c4qc-4q9p-m9q9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-c4qc-4q9p-m9q9/GHSA-c4qc-4q9p-m9q9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c4qc-4q9p-m9q9
Aliases
Downstream
CGA (30)
MINI (19)
Published
2026-02-10T12:30:28Z
Modified
2026-09-10T03:50:59Z
Severity
  • 1.0 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N CVSS Calculator
Summary
Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability
Details

Observable Timing Discrepancy vulnerability in Apache Shiro.

This issue affects Apache Shiro: from 1., 2. before 2.0.7.

Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue.

Prior to Shiro 2.0.7, code paths for non-existent vs. existing users are different enough, that a brute-force attack may be able to tell, by timing the requests only, determine if the request failed because of a non-existent user vs. wrong password.

The most likely attack vector is a local attack only. Shiro security model  https://shiro.apache.org/security-model.html#username_enumeration  discusses this as well.

Typically, brute force attack can be mitigated at the infrastructure level.

Database specific
{
    "cwe_ids":  [
        "CWE-208"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-10T14:33:33Z",
    "nvd_published_at":  "2026-02-10T10:15:59Z",
    "severity":  "LOW"
}
References

Affected packages

Maven / org.apache.shiro:shiro-core

Package

Name
org.apache.shiro:shiro-core
View open source insights on deps.dev
Purl
pkg:maven/org.apache.shiro/shiro-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.0

Affected versions

1.*
1.0.0-incubating
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.3.0
1.3.1
1.3.2
1.4.0-RC2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
2.*
2.0.0-alpha-1
2.0.0-alpha-2
2.0.0-alpha-3
2.0.0-alpha-4
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-c4qc-4q9p-m9q9/GHSA-c4qc-4q9p-m9q9.json"