PT-2026-24894 · Perfree · Go-Fastdfs-Web

Din4

+1

·

Published

2026-03-11

·

Updated

2026-03-12

·

CVE-2026-3963

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions perfree go-fastdfs-web versions through 1.3.7
Description A security issue has been identified in the rememberMeManager function within the Apache Shiro RememberMe component of perfree go-fastdfs-web. This function, located in the file src/main/java/com/perfree/config/ShiroConfig.java, utilizes a hard-coded cryptographic key. This allows for remote attacks, though the complexity is considered high and exploitability is reported as difficult. The exploit for this issue has been publicly released. The vendor was notified but did not respond.
Recommendations Versions through 1.3.7 should be updated to a newer, secure version as soon as it becomes available. As a temporary workaround, consider disabling the RememberMe functionality within the Apache Shiro configuration until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-3963

Affected Products

Go-Fastdfs-Web