{"api_version":"v1","generated_at":"2026-10-05T20:50:00+00:00","product":{"cve_count":17,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-shiro-03d2e050cbf6","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Shiro","next_cursor":null,"observations":[{"affected":"2.0.0-alpha-0 \u2264 3.0.0","affected_versions_present":true,"cve_id":"CVE-2026-58301","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-58301","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-31T15:29:49.700Z","patch_url":"","primary_source":"","published":"2026-08-31T07:40:37.337Z"},{"affected":"\u2264 2.99.99; 3.0.0-alpha-0 \u2264 3.0.0-alpha-1","affected_versions_present":true,"cve_id":"CVE-2026-56091","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56091","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-25T12:10:34.365Z","patch_url":"","primary_source":"","published":"2026-06-25T08:45:19.426Z"},{"affected":"1.2.4 \u2264 2.99.99; 3.0.0-alpha-0 \u2264 3.0.0-alpha-1","affected_versions_present":true,"cve_id":"CVE-2026-56130","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56130","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-25T12:12:43.666Z","patch_url":"","primary_source":"","published":"2026-06-25T08:44:30.040Z"},{"affected":"\u2264 2.2.0; 3.0.0-alpha-0 \u2264 3.0.0-alpha-1","affected_versions_present":true,"cve_id":"CVE-2026-49268","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49268","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-17T17:02:22.861Z","patch_url":"","primary_source":"","published":"2026-06-17T13:07:44.488Z"},{"affected":"2.0.0-alpha-0 \u2264 2.2.0; 3.0.0-alpha-0 \u2264 3.0.0-alpha-1","affected_versions_present":true,"cve_id":"CVE-2026-48589","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48589","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T12:37:44.475Z","patch_url":"","primary_source":"","published":"2026-05-25T20:20:03.597Z"},{"affected":"1.0 \u2264 2.1.0; 3.0.0-alpha-0 \u2264 3.0.0-alpha-1","affected_versions_present":true,"cve_id":"CVE-2026-43828","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-43828","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T12:38:38.399Z","patch_url":"","primary_source":"","published":"2026-05-25T20:19:26.227Z"},{"affected":"1.0 \u2264 2.1.0; 3.0.0-alpha-0 \u2264 3.0.0-alpha-1","affected_versions_present":true,"cve_id":"CVE-2026-43827","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-43827","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T12:39:39.186Z","patch_url":"","primary_source":"","published":"2026-05-25T20:19:03.428Z"},{"affected":"< 2.0.7","affected_versions_present":true,"cve_id":"CVE-2026-23901","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23901","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-10T15:31:25.166Z","patch_url":"","primary_source":"","published":"2026-02-10T09:25:51.765Z"},{"affected":"< 2.0.7","affected_versions_present":true,"cve_id":"CVE-2026-23903","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23903","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-20T09:44:32.338Z","patch_url":"","primary_source":"","published":"2026-02-09T09:26:21.772Z"},{"affected":"< 1.13.0; 2.0.0-alpha-1 < 2.0.0-alpha-4","affected_versions_present":true,"cve_id":"CVE-2023-46749","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-46749","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-11-03T21:50:03.484Z","patch_url":"https://access.redhat.com/security/cve/CVE-2023-46749","primary_source":"","published":"2024-01-15T09:57:31.613Z"},{"affected":"< 1.13.0; 2.0.0-alpha-1 < 2.0.0-alpha-4","affected_versions_present":true,"cve_id":"CVE-2023-46750","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-46750","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-03T21:50:05.435Z","patch_url":"","primary_source":"","published":"2023-12-14T08:15:58.031Z"},{"affected":"< 1.12.0; < 2.0.0-alpha-3","affected_versions_present":true,"cve_id":"CVE-2023-34478","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-34478","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T16:55:37.269Z","patch_url":"","primary_source":"","published":"2023-07-24T18:24:45.619Z"},{"affected":"See the vendor and CVE records for the affected range.","affected_versions_present":false,"cve_id":"CVE-2023-22602","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22602","fixed":"< 1.11.0","last_modified":"2024-08-02T10:13:49.411Z","patch_url":"https://lists.apache.org/thread/dzj0k2smpzzgj6g666hrbrgsrlf9yhkl","primary_source":"","published":"2023-01-14T09:33:39.775Z"},{"affected":"Apache Shiro < 1.10.0","affected_versions_present":true,"cve_id":"CVE-2022-40664","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-40664","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-15T15:02:41.513Z","patch_url":"","primary_source":"","published":"2022-10-12T00:00:00.000Z"},{"affected":"Before 1.9.1","affected_versions_present":true,"cve_id":"CVE-2022-32532","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-32532","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-03T07:46:43.634Z","patch_url":"","primary_source":"","published":"2022-06-28T23:20:11.000Z"},{"affected":"Apache Shiro < 1.8.0","affected_versions_present":true,"cve_id":"CVE-2021-41303","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-41303","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T03:08:32.012Z","patch_url":"https://www.oracle.com/security-alerts/cpujul2022.html","primary_source":"","published":"2021-09-17T08:20:12.000Z"},{"affected":"Apache Shiro 1.5.2 - 1.5.3","affected_versions_present":true,"cve_id":"CVE-2020-11989","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-11989","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T11:48:57.710Z","patch_url":"","primary_source":"","published":"2020-06-22T18:06:37.000Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"Apache Software Foundation"}}
