CVE-2026-80181
NONE—CVSS v3
—CVSS v2
0.21%
EPSS (exploit probability)
CWE-918CWE
Description
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: through 1.20.0.
Users are recommended to upgrade to version 1.21.0, which fixes the issue.
Affected routers (0)
No routers currently mapped to this CVE in our database.