Published:2026/08/18 Last Updated:2026/08/18
JVN#06609828
Apache Allura vulnerable to server-side request forgery
Overview
Apache Allura provided by The Apache Software Foundation contains a server-side request forgery vulnerability.
Products Affected
- Apache Allura versions prior to 1.19.1
Description
Apache Allura provided by The Apache Software Foundation contains the vulnerability listed below:
- Server-side request forgery (CWE-918)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L Base Score 5.1
- CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L Base Score 6.6
- CVE-2026-69223
Impact
An attacker could use webhooks to send arbitrary requests to internal network URLs accessible from the affected product.
Solution
Update the Software
Update the software to the latest version according to the information provided by the developer.
Vendor Status
| Vendor | Link |
| The Apache Software Foundation | Apache Allura 1.19.1 released, with many security fixes |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Satoshi Ogawa of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
|
| JVN iPedia |
JVNDB-2026-000116 |