CVE-2026-82375: Apache Roller: Server-side request forgery via entry trackback and enclosure URLs
Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handling. The Trackback control is hidden in the standard UI, but its action remains directly reachable; the enclosure path is relevant only when an author supplies an enclosure URL. No non-default server configuration is required, and the default empty Trackback allow-list permits all destinations. Requests can reach loopback and private-network addresses, while enclosure handling exposes response status, content type, and length. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes the outbound trackback action and stops dereferencing enclosure URLs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Rollerto a version that resolves this vulnerability.Fixed in 6.1.6
Event History
Frequently Asked Questions
Which users can trigger the vulnerable requests?
An authenticated user must have entry-editing rights on a weblog. No user interaction is required.
Are standard deployments exposed without additional configuration?
Yes. No non-default server configuration is required, and the default empty Trackback allow-list permits all destinations.
What internal targets and response information may be exposed?
Requests can reach loopback and private-network addresses. For enclosure URLs supplied by an author, the handling exposes the response status, content type, and length.
What version should be deployed to remediate the issue?
Upgrade to Apache Roller 6.1.6 or later. That release removes the outbound Trackback action and stops dereferencing enclosure URLs.