THREATOPS
THREAT OPSThreat News › CVE-2026-58301: Apache Shiro: Server-side POST request may be steered to an alternate host

CVE-2026-58301: Apache Shiro: Server-side POST request may be steered to an alternate host

medoss_secPublished 2026-08-30

<p>Posted by Lenny Primak on Aug 30</p>Severity: <br /> <br /> Affected versions:<br /> <br /> - Apache Shiro (org.apache.shiro:shiro-jakata-ee) 2.0.0-alpha-0 through 3.0.0<br /> <br /> Description:<br /> <br /> When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that <br /> causes the server to initiate a connection to an attacker-cont

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/614