Open redirect in Apache Shiro - CVE-2026-48589
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an arbitrary site.
The vulnerability exists due to improper input validation in the post-login redirect flow of the shiro-jakarta-ee integration module when processing the HTTP Referer header. A remote attacker can supply a crafted Referer header to redirect users to an arbitrary site.
The issue occurs only in applications using the Jakarta EE integration module.