CVE-2026-82375: Apache Roller: Server-side request forgery via entry trackback and enclosure URLs
Apache Roller 6.1.5 lets weblog editors trigger SSRF through trackback and enclosure URLs.
Apache disclosed CVE-2026-82375, a server-side request forgery issue in Apache Roller 6.1.5. An authenticated user with entry-editing rights can cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handling. The project notes the Trackback control is hidden in the standard interface. CVSS 3.1 is 7.4 (AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L), rated moderate by the project, with no stated in-the-wild exploitation.
- CVE-2026-82375 is an SSRF flaw in Apache Roller 6.1.5.
- Editors can trigger outbound HTTP requests via trackback or enclosure URLs.
- The standard Trackback control is hidden, but the legacy path remains.
- CVSS 3.1 is 7.4 with low confidentiality, integrity, and availability impact.
- Exploitation in the wild is not mentioned.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82375 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 7.4 (high) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L Affected versions: - Apache Roller 6.1.5 Description: Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handling. The Trackback control is hidden in the standard...
This source does not provide full text. Read it at seclists.org.