Junglewise Threat Intelligence

CVE-2026-80181: Apache Allura SSRF in webhooks

CVE-2026-80181 · Severity: critical · CVSS 9.1 · Published 2026-09-04

Technologies: Apache Allura. Vendors: Apache.

Executive brief

Apache Allura is a web-based project management and collaboration platform used for source code hosting, issue tracking, and team communication. A Server-Side Request Forgery (SSRF) vulnerability in its webhook feature allows attackers to make unauthorized requests from the server to internal resources or external systems, potentially exposing sensitive data or enabling lateral movement within the network.

Technical details

Apache Allura's webhook functionality is vulnerable to Server-Side Request Forgery (SSRF), where an attacker can manipulate webhook URLs to cause the server to make requests to arbitrary internal or external targets. The vulnerability exists in versions through 1.20.0 and is reachable via the webhook configuration interface. An attacker with access to create or modify webhooks can leverage this to access internal services, retrieve sensitive information, or perform actions on behalf of the server. The fix is available in version 1.21.0.

Affected products

  • Apache Allura through 1.20.0

Timeline

  • 2026-09-03: disclosed
  • 2026-09-04: patched: Fix available in version 1.21.0

References

Related threats