Server-Side Request Forgery Vulnerability in Apache Allura
CVE-2026-80181
Currently unrated
What is CVE-2026-80181?
A vulnerability in Apache Allura allows for Server-Side Request Forgery (SSRF) through the use of webhooks. This flaw can potentially be exploited to send unauthorized requests from the server. Affected versions are up to 1.20.0, and users are advised to upgrade to version 1.21.0 to mitigate this security risk.
Affected Version(s)
Apache Allura 0 <= 1.20.0