Blog Better! Roller is the open source Java blog server that drives Apache Software Foundation blogs and others. Read more on the about page.

Site hosted by Digital Ocean



« Apache Roller 6.1.6... | Main

Apache Roller 6.1.6 fixes 18 security vulnerabilities

09.27.2026 by Dave Johnson | 0 Comments

Apache Roller 6.1.6 fixes 18 security vulnerabilities. Apache Roller 6.1.5 is affected. Upgrade to 6.1.6 now.

Every installation should upgrade. Some vulnerabilities need no optional feature. Vulnerabilities were found in these features:

  • Comments & Trackbacks, LDAP comment authentication
  • Multiple users and weblogs
  • Media file uploads
  • The frontpage theme
  • XML-RPC (MetaWeblog or Blogger API), even when disabled
  • AtomPub with WSSE authentication
  • OAuth

Each CVE links to its advisory.

Critical

Important

Moderate

Some changes affect existing installations. Read the release notes before you upgrade.

Thanks to the reporters and to everyone who reviewed and tested the fixes.

« Apache Roller 6.1.6... | Main