Unintended Proxy or Intermediary in Apache Shiro - CVE-2026-58301
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to cause the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data.
The vulnerability exists due to improper access control in the Jakarta EE integration module when resubmitting a form via an HTTP POST request. A remote user can craft a specially crafted HTTP request to cause the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data.
Only deployments that use the Jakarta EE integration module are vulnerable.