Severity: important Affected versions:
- Apache Allura before 1.19.1 Description: Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. References: https://allura.apache.org/posts/2026-allura-1.19.1.html https://allura.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-69223
