CVE-2026-69223

NONE
Updated Aug 11, 2026
Apache
Parameter Value
Affected Versions before 1.19.1.
Fixed In 1.19.1
Type CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Apache
Public PoC No

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.