{
  "from_raw": "Lenny Primak <lprimak@apache.org>",
  "from": "Lenny Primak <lp...@apache.org>",
  "gravatar": "3412c78813a07ca863c82de7fc207fd7",
  "to": "an...@apache.org,\n de...@shiro.apache.org",
  "subject": "CVE-2026-58301: Apache Shiro: Server-side POST request may be steered to an alternate host",
  "message-id": "<eb89b3a9-fab2-d791-efe3-cd4ca9e61b2a@apache.org>",
  "mid": "0f0cxdz3joz0q23jg9oc1ojc3cbvjdwx",
  "permalinks": [
    "0f0cxdz3joz0q23jg9oc1ojc3cbvjdwx",
    "r5895dae91d77af2e9583d7576bd87f3704e246b872d6a5072ef23b97@<announce.apache.org>"
  ],
  "dbid": "f2f35f3245d5f592ae463e8c12bed4a0ec781a41b5bef1f9c98b87c1b5d195f6",
  "cc": "de...@shiro.apache.org",
  "epoch": 1788120147,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/08/30 20:02:27",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: \n\nAffected versions:\n\n- Apache Shiro (org.apache.shiro:shiro-jakata-ee) 2.0.0-alpha-0 through 3.0.0\n\nDescription:\n\nWhen Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Apache Shiro versions 2.x through 3.0.0 only in deployments that use the Jakarta EE integration module.\n\nMitigation: Upgrade to version 3.0.1 or later, which fixes the issue. +\nAlternatively, you can set the `org.apache.shiro.form-resubmit-host` (String) and `org.apache.shiro.form-resubmit-port` (Integer) system properties to restrict the host and port that Shiro will connect to when resubmitting a form.\n\nCredit:\n\nliyi.zhou@sydney.edu.au (Liyi), https://lzhou1110.github.io/ (finder)\nziyue0530@gmail.com (Ziyue), https://zyy0530.github.io/ (finder)\ncshe0476@uni.sydney.edu.au (Strick), https://str1ckl4nd.github.io/ (finder)\nchng0012@uni.sydney.edu.au (Maurice), http://maurice.busystar.org/ (finder)\ncyu210608@gmail.com (Chenchen), https://7thparkk.github.io/ (finder)\nLenny Primak <le...@flowlogix.com> (remediation developer)\nAndrea Cosentino (remediation reviewer)\n\nReferences:\n\nhttps://shiro.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-58301\n\n",
  "body_short": "Severity: \n\nAffected versions:\n\n- Apache Shiro (org.apache.shiro:shiro-jakata-ee) 2.0.0-alpha-0 through 3.0.0\n\nDescription:\n\nWhen Apache Shiro is used with the Jakarta EE integration module, a low-priv",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3981,
  "id": "0f0cxdz3joz0q23jg9oc1ojc3cbvjdwx"
}