Published:2026/08/18  Last Updated:2026/08/18

JVN#06609828
Apache Allura vulnerable to server-side request forgery

Overview

Apache Allura provided by The Apache Software Foundation contains a server-side request forgery vulnerability.

Products Affected

  • Apache Allura versions prior to 1.19.1

Description

Apache Allura provided by The Apache Software Foundation contains the vulnerability listed below:

  • Server-side request forgery (CWE-918)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L Base Score 5.1
    • CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L Base Score 6.6
    • CVE-2026-69223

Impact

An attacker could use webhooks to send arbitrary requests to internal network URLs accessible from the affected product.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Link
The Apache Software Foundation Apache Allura 1.19.1 released, with many security fixes

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Satoshi Ogawa of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2026-000116