Skip to content

Apache Roller: information disclosure

Medium6.5CVE-2026-82385 · Published Sep 28, 2026 · updated Sep 29, 2026

Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller configuration files containing secrets, by authoring a Velocity template that uses an include directive to load a classpath resource outside the theme namespace. Roller treats weblog administrators as untrusted and enables a Velocity sandbox, but the include and parse directives are not confined by it. No non-default configuration is required; this affects any weblog whose administrator can author templates. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which confines includes to the active theme and removes classpath resource loading from weblog rendering.

Affected versions

PackageAffectedFixed in
Apache Roller
Product
<= 6.1.5No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Karaf: command injection
High8.8Sep 28
LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and...
High7.3Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: missing authentication
High8.2Sep 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.