GHSA-c244-p6m5-vqj6
Apache Shiro has an Authentication Bypass
Quick fix
GHSA-c244-p6m5-vqj6 — org.apache.shiro:shiro-spring: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.1.0</version> for org.apache.shiro:shiro-springDetails
### Impact
**Authentication Bypass:** A vulnerability exists in Apache Shiro that allows authentication bypass for static files when served from a case-insensitive filesystem (such as the default configuration on macOS or Windows).
The issue arises when Shiro's URL filters are configured with lower-case rules (a common default), but the underlying operating system treats mixed-case filenames as identical. An attacker can access protected static resources by varying the capitalization of the filename in the request (e.g., requesting `/SECRET.TXT` to bypass a rule for `/secret.txt`).
This issue specifically affects static file handling and does not impact dynamic resource paths that are case-sensitive.
### Patches Users should upgrade to Apache Shiro **2.1.0** or later.
**Important Configuration Note:** Version 2.1.0 introduces a new configuration parameter to handle case-insensitivity, which must be enabled manually to resolve the issue:
* **shiro.ini:** ```ini filterChainResolver.caseInsensitive = true ``` * **Spring Boot (application.properties):** ```properties shiro.caseInsensitive=true ```
*Note: Apache Shiro 3.0.0 (upcoming) will enable this setting by default.*
### Workarounds * Ensure that the filesystem hosting the application is case-sensitive (e.g., Linux/Unix). * Manually configure all Shiro filter chains to handle all possible case variations of protected filenames (not recommended due to complexity).
### Resources * [CVE-2026-23903](https://nvd.nist.gov/vuln/detail/CVE-2026-23903) * [Mailing List Announcement](https://lists.apache.org/thread/5jjf0hnjcol58z2m5y255c7scz1lnp8k) * [OSS-Security List](http://www.openwall.com/lists/oss-security/2026/02/08/1)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.1.0# pom.xml: bump <version>2.1.0</version> for org.apache.shiro:shiro-springReferences
- https://nvd.nist.gov/vuln/detail/CVE-2026-23903[ADVISORY]
- https://github.com/apache/shiro/commit/3b9638b957495004599aeaf24ba8949e309f26e8[WEB]
- https://github.com/apache/shiro[PACKAGE]
- https://lists.apache.org/thread/5jjf0hnjcol58z2m5y255c7scz1lnp8k[WEB]
- http://www.openwall.com/lists/oss-security/2026/02/08/1[WEB]