CVE-2026-82375
Received Received - Intake

Server-Side Request Forgery in Apache Roller

Vulnerability report for CVE-2026-82375, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Apache Software Foundation

Description

Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handling. The Trackback control is hidden in the standard UI, but its action remains directly reachable; the enclosure path is relevant only when an author supplies an enclosure URL. No non-default server configuration is required, and the default empty Trackback allow-list permits all destinations. Requests can reach loopback and private-network addresses, while enclosure handling exposes response status, content type, and length. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes the outbound trackback action and stops dereferencing enclosure URLs.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache roller 6.1.5
apache roller From 6.1.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in Apache Roller 6.1.5. An authenticated user with entry-editing rights can make outbound HTTP requests to any chosen destination through legacy Trackback and entry enclosure features. The Trackback feature is hidden but still accessible, and the enclosure feature processes URLs provided by authors. Both features allow requests to internal or private network addresses. Upgrading to version 6.1.6 or later removes these vulnerable features.

The vulnerability exists because the application still processes Trackback and enclosure URLs without proper restrictions. The default configuration allows all destinations, and the code paths for these features were dormant but remained functional.

Detection Guidance

To detect this SSRF vulnerability in Apache Roller 6.1.5, check for outbound HTTP requests originating from the application, particularly to loopback or private-network addresses. Review server logs for legacy Trackback or enclosure URL handling requests. Verify if the Trackback action endpoint is accessible or if enclosure URLs are being dereferenced.

Impact Analysis

An attacker with entry-editing access could send requests to internal systems, potentially accessing sensitive data or services. For enclosure handling, the attacker could learn response details like status, content type, and length of internal resources. This could lead to information disclosure or further attacks on internal infrastructure.

The impact is limited to authenticated users with specific privileges. Unauthenticated users cannot exploit this directly. The vulnerability does not allow code execution but could be used to probe internal networks or exfiltrate data.

Compliance Impact

This vulnerability could lead to unauthorized access to internal systems, potentially violating data protection requirements under GDPR or HIPAA. If sensitive data is exposed through SSRF, it may result in compliance breaches, unauthorized data processing, or failure to maintain adequate security measures.

Mitigation Strategies

Upgrade Apache Roller to version 6.1.6 or later to remove the vulnerable Trackback functionality and stop dereferencing enclosure URLs. If upgrading is not immediately possible, restrict outbound network access from the application server and disable legacy Trackback features manually.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82375. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart