{"id":"GHSA-c244-p6m5-vqj6","summary":"Apache Shiro has an Authentication Bypass","details":"### Impact\n\n**Authentication Bypass:**\nA vulnerability exists in Apache Shiro that allows authentication bypass for static files when served from a case-insensitive filesystem (such as the default configuration on macOS or Windows).\n\nThe issue arises when Shiro's URL filters are configured with lower-case rules (a common default), but the underlying operating system treats mixed-case filenames as identical. An attacker can access protected static resources by varying the capitalization of the filename in the request (e.g., requesting `/SECRET.TXT` to bypass a rule for `/secret.txt`).\n\nThis issue specifically affects static file handling and does not impact dynamic resource paths that are case-sensitive.\n\n### Patches\nUsers should upgrade to Apache Shiro **2.1.0** or later.\n\n**Important Configuration Note:**\nVersion 2.1.0 introduces a new configuration parameter to handle case-insensitivity, which must be enabled manually to resolve the issue:\n\n* **shiro.ini:**\n    ```ini\n    filterChainResolver.caseInsensitive = true\n    ```\n* **Spring Boot (application.properties):**\n    ```properties\n    shiro.caseInsensitive=true\n    ```\n\n*Note: Apache Shiro 3.0.0 (upcoming) will enable this setting by default.*\n\n### Workarounds\n* Ensure that the filesystem hosting the application is case-sensitive (e.g., Linux/Unix).\n* Manually configure all Shiro filter chains to handle all possible case variations of protected filenames (not recommended due to complexity).\n\n### Resources\n* [CVE-2026-23903](https://nvd.nist.gov/vuln/detail/CVE-2026-23903)\n* [Mailing List Announcement](https://lists.apache.org/thread/5jjf0hnjcol58z2m5y255c7scz1lnp8k)\n* [OSS-Security List](http://www.openwall.com/lists/oss-security/2026/02/08/1)","aliases":["CVE-2026-23903"],"modified":"2026-07-17T21:07:51.427452771Z","published":"2026-02-09T12:30:22Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-02-11T19:48:43Z","nvd_published_at":"2026-02-09T10:15:57Z","cwe_ids":["CWE-289"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23903"},{"type":"WEB","url":"https://github.com/apache/shiro/commit/3b9638b957495004599aeaf24ba8949e309f26e8"},{"type":"PACKAGE","url":"https://github.com/apache/shiro"},{"type":"WEB","url":"https://lists.apache.org/thread/5jjf0hnjcol58z2m5y255c7scz1lnp8k"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/02/08/1"}],"affected":[{"package":{"name":"org.apache.shiro:shiro-spring","ecosystem":"Maven","purl":"pkg:maven/org.apache.shiro/shiro-spring"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0"}]}],"versions":["1.0.0-incubating","1.1.0","1.10.0","1.10.1","1.11.0","1.12.0","1.13.0","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.3.0","1.3.1","1.3.2","1.4.0","1.4.0-RC2","1.4.1","1.4.2","1.5.0","1.5.1","1.5.2","1.5.3","1.6.0","1.7.0","1.7.1","1.8.0","1.9.0","1.9.1","2.0.0","2.0.0-alpha-1","2.0.0-alpha-2","2.0.0-alpha-3","2.0.0-alpha-4","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-c244-p6m5-vqj6/GHSA-c244-p6m5-vqj6.json","last_known_affected_version_range":"\u003c= 2.0.6"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}