SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-80181

CRITICAL · CVSS 9.1 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Apache Allura's webhooks are susceptible to Server-Side Request Forgery (SSRF), potentially allowing attackers to manipulate requests sent from the server to internal resources. This vulnerability impacts all versions up to 1.20.0, and users are strongly advised to upgrade to version 1.21.0 to mitigate the risk. Organizations utilizing Apache Allura should prioritize this update to protect against potential exploitation.

CVE
CVE-2026-80181
Severity
CRITICAL
CVSS
9.1
EPSS
0.40%
Apache

Original NVD Description

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.