THREATOPS
THREAT OPSThreat News › CVE-2026-80181: Apache Allura: Server-side request forgery

CVE-2026-80181: Apache Allura: Server-side request forgery

medoss_secPublished 2026-09-03

<p>Posted by Dave Brondsema on Sep 03</p>Severity: important<br /> <br /> Affected versions:<br /> <br /> - Apache Allura through 1.20.0<br /> <br /> Description:<br /> <br /> Apache Allura&apos;s webhooks are vulnerable to Server-Side Request Forgery (SSRF).<br /> <br /> This issue affects Apache Allura: through 1.20.0.<br /> <br /> Users are recommended to upgrade to version 1.21.0, which fixes

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/644