Server-Side Request Forgery Vulnerability in Apache Allura
CVE-2026-80181

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
4 September 2026

What is CVE-2026-80181?

A vulnerability in Apache Allura allows for Server-Side Request Forgery (SSRF) through the use of webhooks. This flaw can potentially be exploited to send unauthorized requests from the server. Affected versions are up to 1.20.0, and users are advised to upgrade to version 1.21.0 to mitigate this security risk.

Affected Version(s)

Apache Allura 0 <= 1.20.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.