CVE-2026-73240

CVE-2026-73240: Apache Allura: Git command injection

Vendor Apache Software Foundation
Product Apache Allura
Weakness CWE-88
Published August 12, 2026
Last update August 13, 2026

CVSS base score

What the vulnerability does

01Description

Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

Key dates

02Disclosure timeline

August 12, 2026 CVE published
August 13, 2026 Record updated