CVE-2026-82375 Details
Description
Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handling. The Trackback control is hidden in the standard UI, but its action remains directly reachable; the enclosure path is relevant only when an author supplies an enclosure URL. No non-default server configuration is required, and the default empty Trackback allow-list permits all destinations. Requests can reach loopback and private-network addresses, while enclosure handling exposes response status, content type, and length. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes the outbound trackback action and stops dereferencing enclosure URLs.
A server-side request forgery (SSRF) vulnerability has been identified in Apache Roller version 6.1.5. This vulnerability allows authenticated users with entry-editing rights to make outbound HTTP requests to destinations of their choice. The issue arises from legacy handling of Trackback and entry enclosure URLs. Although the Trackback control is not visible in the standard user interface, it can still be accessed directly. The enclosure path is only relevant when an author provides an enclosure URL. The vulnerability does not require any non-default server configuration, and the default Trackback allow-list permits all destinations. Exploitation of this vulnerability can reach loopback and private-network addresses. Additionally, the enclosure handling reveals response status, content type, and length.
Users are advised to upgrade to Apache Roller version 6.1.6 or later, which addresses this vulnerability by removing the outbound Trackback action and discontinuing the dereferencing of enclosure URLs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/25/8 | CVE | AdvisoryMailing ListRemedy |
| https://github.com/apache/roller/pull/163 | [email protected] | Issue TrackingVendor |
| https://github.com/apache/roller/pull/175 | [email protected] | Issue TrackingVendor |
| https://lists.apache.org/thread/0p7kc0rjcpj3rf00cp96zfkfrz0ns4ny | [email protected] | AdvisoryMailing ListRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Apache Roller | 6.1.5 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | CVE Modified | CVE |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion