openwall.com
http://www.openwall.com/lists/oss-security/2026/05/25/7 CVE-2026-43828
MEDIUM
Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default
Record summary
CVE-2026-43828 has a selected CVSS score of 5.9 (medium).
Description
Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 26, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 1.0 to ≤ 2.1.0 | affected |
| 3.0.0-alpha-0 to ≤ 3.0.0-alpha-1 | affected | ||
org.apache.shiro:shiro-webBrowse Maven / org.apache.shiro:shiro-web | GitHub Advisory | 1.0.0-incubating to < 2.2.0 · Fixed in 2.2.0 | affected |
| 3.0.0-alpha-1 | affected | ||
| 3.0.0-alpha-1 to < 3.0.0-alpha-2 · Fixed in 3.0.0-alpha-2 | affected |
References
4github.com
https://github.com/apache/shiro nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-43828 shiro.apache.orgVendor advisory
https://shiro.apache.org/security-reports.html