Stored XSS Vulnerability in Apache Allura by Apache
CVE-2026-80190

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
4 September 2026

What is CVE-2026-80190?

Apache Allura has been identified with a stored XSS vulnerability that exploits SVN code repositories. Git repositories remain unaffected. This vulnerability could allow attackers to execute scripts in the context of a user's session. It is recommended that users upgrade to version 1.21.0 as it addresses the issue effectively. The risk associated with this vulnerability is likely mitigated through default Content Security Policy (CSP) headers.

Affected Version(s)

Apache Allura 0 <= 1.20.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.