CVE-2026-69223
Description
AI Translation Available
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: before 1.19.1.
Users are recommended to upgrade to version 1.19.1, which fixes the issue.
918
Server-Side Request Forgery (SSRF)
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Access Control
Potential Impacts:
Read Application Data
Execute Unauthorized Code Or Commands
Bypass Protection Mechanism
Applicable Platforms
Technologies:
Web Based, AI/ML, Web Server
http://www.openwall.com/lists/oss-security/2026/08/11/4
https://allura.apache.org/posts/2026-allura-1.19.1.html
https://lists.apache.org/thread/9xpltfm6nombd7rdrx5o0hh8kxmm82pb