Server-Side Request Forgery in Apache Roller Affects Weblogs
CVE-2026-82375
What is CVE-2026-82375?
A Server-Side Request Forgery (SSRF) vulnerability exists in Apache Roller 6.1.5, allowing authenticated users with entry-editing permissions to send outbound HTTP requests to arbitrary destinations. This is achievable through the utilization of legacy outbound Trackback and entry enclosure functionalities, which remain accessible despite being concealed in the standard UI. Notably, a default empty Trackback allow-list facilitates unrestricted access to all destinations, including loopback and private network addresses. Moreover, enclosure handling can expose critical information such as response status, content type, and length. Users are strongly encouraged to update to Apache Roller 6.1.6 or later, where the problematic outbound Trackback action has been removed, and dereferencing of enclosure URLs is curtailed.
Affected Version(s)
Apache Roller 6.1.5