Server-Side Request Forgery Vulnerability in Apache Allura
CVE-2026-69223
9.1CRITICAL
What is CVE-2026-69223?
Apache Allura suffers from a Server-Side Request Forgery (SSRF) vulnerability due to insecure webhook handling. This allows an attacker to send arbitrary requests from the server to internal or external resources, potentially exposing sensitive information. Users should promptly upgrade to version 1.19.1 to mitigate this issue and enhance security.
Affected Version(s)
Apache Allura 0 < 1.19.1