Project Roller
Blogs, news and views
Blog Better! Roller is the open source Java blog server that drives Apache Software Foundation blogs and others. Read more on the about page.
Quick Links
Navigation
Apache Roller 6.1.6 fixes 18 security vulnerabilities
09.27.2026 by Dave Johnson | 0 Comments
Apache Roller 6.1.6 fixes 18 security vulnerabilities. Apache Roller 6.1.5 is affected. Upgrade to 6.1.6 now.
Every installation should upgrade. Some vulnerabilities need no optional feature. Vulnerabilities were found in these features:
- Comments & Trackbacks, LDAP comment authentication
- Multiple users and weblogs
- Media file uploads
- The frontpage theme
- XML-RPC (MetaWeblog or Blogger API), even when disabled
- AtomPub with WSSE authentication
- OAuth
Each CVE links to its advisory.
Critical
- CVE-2026-82384: Unauthenticated XML-RPC deserialization
Important
- CVE-2026-82348: Cross-weblog resource tampering
- CVE-2026-82376: XXE in trackback parser
- CVE-2026-82380: CSRF protection bypass
- CVE-2026-82381: Stored XSS in authoring UI
- CVE-2026-82383: Anonymous setup tampering
- CVE-2026-82385: Velocity template sandbox escape
- CVE-2026-82386: XXE in OPML import
- CVE-2026-86507: Stored XSS in comment moderation
Moderate
- CVE-2026-82375: SSRF via trackback and enclosure
- CVE-2026-82377: Missing XML-RPC weblog authorization
- CVE-2026-82378: OAuth endpoint trusts request identity
- CVE-2026-82379: WSSE authentication replay
- CVE-2026-82382: Reflected XSS in frontpage
- CVE-2026-82387: Stored XSS via media type
- CVE-2026-82546: Stored XSS via trackback links
- CVE-2026-91204: Stored javascript: URI in comments
- CVE-2026-91206: Reflected XSS in LDAP authenticator
Some changes affect existing installations. Read the release notes before you upgrade.
Thanks to the reporters and to everyone who reviewed and tested the fixes.
Apache Roller 6.1.6 released
09.24.2026 by Dave Johnson | 0 Comments
The Apache Roller project is pleased to announce Apache Roller 6.1.6.
Roller is a full-featured, multi-user and group-blog server written in Java, suitable for blog sites large and small.
This is a maintenance release with bug fixes and small improvements. Users of 6.1.5 and earlier are encouraged to upgrade.
A few changes affect existing installations:
- Initial setup now requires a one-time token that Roller prints to the server log. This applies both to a new installation and to a restart that migrates the database schema.
- Incoming and outbound Trackback support is removed. The endpoint no longer exists and the entry editor no longer sends pings.
- WSSE AtomPub authentication is retired. The authentication.method setting now takes basic or oauth, and an installation still set to wsse fails on startup, so change it before you upgrade.
- Media file content types are derived from file content rather than from the upload request.
- Table detection during installation is scoped to the database the connection points at. This fixes MySQL installs into an empty schema on a server that also hosts another Roller database.