{
  "from_raw": "Dave Brondsema <brondsem@apache.org>",
  "from": "Dave Brondsema <br...@apache.org>",
  "gravatar": "d5e986d2eb0e6a4349e0ee8e74560158",
  "to": "an...@apache.org,\n de...@allura.apache.org,\n us...@allura.apache.org",
  "subject": "CVE-2026-75099: Apache Allura: Unauthenticated REST disclosure",
  "message-id": "<fb8a1ec9-c650-4a1a-86c6-83a35b9f3877@apache.org>",
  "mid": "bt9hxkpp4ys28vb7sh3x7k4b6rs4l87k",
  "permalinks": [
    "bt9hxkpp4ys28vb7sh3x7k4b6rs4l87k",
    "r8a122ca13c91da641aaca4aededfd2aad018d24df54a51d98a7df5b7@<announce.apache.org>"
  ],
  "dbid": "6be47a39f66d1e68e96ccf0a3146b5f6b007559e14b21f0e4a5960072e55ddf2",
  "cc": "de...@allura.apache.org",
  "epoch": 1787588340,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/08/24 16:19:00",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important\n\nAffected versions:\n\n- Apache Allura through 1.19.1\n\nDescription:\n\nUnauthenticated REST disclosure of certain content items in Apache Allura.\n\nThis issue affects Apache Allura: through 1.19.1.\n\nUsers are recommended to upgrade to version 1.20.0, which fixes the issue.\n\nCredit:\n\nVenkatraman Kumar, securin.io (finder)\n\nReferences:\n\nhttps://allura.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-75099\n\n",
  "body_short": "Severity: important\n\nAffected versions:\n\n- Apache Allura through 1.19.1\n\nDescription:\n\nUnauthenticated REST disclosure of certain content items in Apache Allura.\n\nThis issue affects Apache Allura: thro",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 4647,
  "id": "bt9hxkpp4ys28vb7sh3x7k4b6rs4l87k"
}