Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY17 SECURITY RECORDS

Apache Software Foundation

Apache Shiro

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-58301 31 Aug 2026 2.0.0-alpha-0 ≤ 3.0.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56091 25 Jun 2026 ≤ 2.99.99; 3.0.0-alpha-0 ≤ 3.0.0-alpha-1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56130 25 Jun 2026 1.2.4 ≤ 2.99.99; 3.0.0-alpha-0 ≤ 3.0.0-alpha-1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-49268 17 Jun 2026 ≤ 2.2.0; 3.0.0-alpha-0 ≤ 3.0.0-alpha-1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48589 25 May 2026 2.0.0-alpha-0 ≤ 2.2.0; 3.0.0-alpha-0 ≤ 3.0.0-alpha-1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-43828 25 May 2026 1.0 ≤ 2.1.0; 3.0.0-alpha-0 ≤ 3.0.0-alpha-1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-43827 25 May 2026 1.0 ≤ 2.1.0; 3.0.0-alpha-0 ≤ 3.0.0-alpha-1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-23901 10 Feb 2026 < 2.0.7 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-23903 9 Feb 2026 < 2.0.7 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-46749 15 Jan 2024 < 1.13.0; 2.0.0-alpha-1 < 2.0.0-alpha-4 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2023-46750 14 Dec 2023 < 1.13.0; 2.0.0-alpha-1 < 2.0.0-alpha-4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-34478 24 Jul 2023 < 1.12.0; < 2.0.0-alpha-3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-22602 14 Jan 2023 See the vendor and CVE records for the affected range. < 1.11.0 Update reference ↗
CVE-2022-40664 12 Oct 2022 Apache Shiro < 1.10.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-32532 28 Jun 2022 Before 1.9.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-41303 17 Sep 2021 Apache Shiro < 1.8.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-11989 22 Jun 2020 Apache Shiro 1.5.2 - 1.5.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.