CVE-2026-82375: Apache Roller: Server-side request forgery via entry trackback and enclosure URLs
Apache Roller 6.1.5 lets weblog editors trigger SSRF through trackback and enclosure URLs.
Apache disclosed CVE-2026-82375, a server-side request forgery issue in Apache Roller 6.1.5. An authenticated user with entry-editing rights can cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handling. The project notes the Trackback control is hidden in the standard interface. CVSS 3.1 is 7.4 (AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L), rated moderate by the project, with no stated in-the-wild exploitation.
44