https://seclists.org/oss-sec/2026/q3/644: CVE-2026-80181: Apache Allura: Server-side quest forgery
Published Sep 3, 2026
·Updated
Affected Software
1 affected component
Apache Allura<=1.20.0
Frequently Asked Questions
1
Which deployments are affected?
Apache Allura versions through 1.20.0 are affected. Version 1.21.0 fixes the issue.
2
What component is involved in exploitation?
The vulnerability is in Apache Allura webhooks. It is an SSRF issue, meaning webhook functionality can be used to make server-side requests.
3
What should teams do if they are running an affected version?
Upgrade Apache Allura to version 1.21.0, which contains the fix.