Server-Side Request Forgery in Apache Roller Affects Weblogs
CVE-2026-82375

7.4HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82375?

A Server-Side Request Forgery (SSRF) vulnerability exists in Apache Roller 6.1.5, allowing authenticated users with entry-editing permissions to send outbound HTTP requests to arbitrary destinations. This is achievable through the utilization of legacy outbound Trackback and entry enclosure functionalities, which remain accessible despite being concealed in the standard UI. Notably, a default empty Trackback allow-list facilitates unrestricted access to all destinations, including loopback and private network addresses. Moreover, enclosure handling can expose critical information such as response status, content type, and length. Users are strongly encouraged to update to Apache Roller 6.1.6 or later, where the problematic outbound Trackback action has been removed, and dereferencing of enclosure URLs is curtailed.

Affected Version(s)

Apache Roller 6.1.5

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

meifukun
n0mi1k
.