This is an automated email from the ASF dual-hosted git repository.
github-actions[bot] pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/solr-site.git
The following commit(s) were added to refs/heads/asf-staging by this push:
new bc3b5eecd Commit build products
bc3b5eecd is described below
commit bc3b5eecdfa6492432ae13390fb6184b85e42b96
Author: Build Pelican (action) <[email protected]>
AuthorDate: Sun Jun 21 18:53:09 2026 +0000
Commit build products
---
output/security-dependency-cves.html | 116 +++++++++++++++++++++++------------
1 file changed, 76 insertions(+), 40 deletions(-)
diff --git a/output/security-dependency-cves.html
b/output/security-dependency-cves.html
index a96bb706e..a483c2367 100644
--- a/output/security-dependency-cves.html
+++ b/output/security-dependency-cves.html
@@ -163,8 +163,8 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
</div>
<h2 id="cve-table">CVE Status for Dependencies <a class="headerlink"
href="#cve-table" title="Permanent link">¶</a></h2>
- <p>Below is a list of CVE vulnerabilities in Apache Solr dependencies and
their applicability to Solr.
- CVEs assessed as exploitable in Solr have their own advisory on the
+ <p>Below is a list of CVE vulnerabilities in Apache Solr dependencies and
their applicability to Solr,
+ with the assessed state of each. CVEs assessed as exploitable in Solr
also have their own advisory on the
<a href="/security-news.html">security news page</a>.</p>
<table>
@@ -177,11 +177,38 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
</tr>
<tr>
<td>
+<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42440">CVE-2026-42440</a>
</td>
+ <td>< 10.1.0</td>
+ <td>
+ opennlp-tools-1.9.4.jar </td>
+ <td><span class="cdx-exploitable">exploitable</span></td>
+ <td><a href="/vex.html#cve-2026-42440">Apache OpenNLP: Out-of-memory
denial of service via crafted model file</a></td>
+ </tr>
+ <tr>
+ <td>
+<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42027">CVE-2026-42027</a>
</td>
+ <td>< 10.1.0</td>
+ <td>
+ opennlp-tools-1.9.4.jar </td>
+ <td><span class="cdx-exploitable">exploitable</span></td>
+ <td><a href="/vex.html#cve-2026-42027">Apache OpenNLP: Arbitrary class
instantiation via model manifest</a></td>
+ </tr>
+ <tr>
+ <td>
+<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40682">CVE-2026-40682</a>
</td>
+ <td>< 10.1.0</td>
+ <td>
+ opennlp-tools-1.9.4.jar </td>
+ <td><span class="cdx-exploitable">exploitable</span></td>
+ <td><a href="/vex.html#cve-2026-40682">Apache OpenNLP: XXE in dictionary
parsing</a></td>
+ </tr>
+ <tr>
+ <td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34481">CVE-2026-34481</a>
</td>
<td>9.10.1, 10.0.0</td>
<td>
log4j-layout-template-json-2.25.3.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2026-34481">Apache Log4j JSON Template
Layout: Invalid JSON for non-finite floating-point values</a></td>
</tr>
<tr>
@@ -190,7 +217,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>9.10.1, 10.0.0</td>
<td>
log4j-core-2.25.3.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2026-34480">Apache Log4j Core: Invalid XML
output from XmlLayout</a></td>
</tr>
<tr>
@@ -199,7 +226,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>9.10.1, 10.0.0</td>
<td>
log4j-1.2-api-2.25.3.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2026-34479">Apache Log4j 1.x bridge:
Malformed XML output from Log4j1XmlLayout</a></td>
</tr>
<tr>
@@ -208,7 +235,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>9.10.1, 10.0.0</td>
<td>
log4j-core-2.25.3.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2026-34478">Apache Log4j Core: Log injection
via CRLF sequences in Rfc5424Layout</a></td>
</tr>
<tr>
@@ -217,7 +244,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>9.10.1, 10.0.0</td>
<td>
log4j-core-2.25.3.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2026-34477">Apache Log4j Core: TLS hostname
verification silently ignored in Socket, SMTP and Syslog appenders</a></td>
</tr>
<tr>
@@ -226,7 +253,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>9.4.0-9.8.1</td>
<td>
zookeeper-3.9.0.jar, zookeeper-3.9.1.jar,
zookeeper-3.9.2.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2024-51504">Apache ZooKeeper: Authentication
bypass with IP-based authentication in Admin Server</a></td>
</tr>
<tr>
@@ -235,7 +262,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>≤ 9.7</td>
<td>
jetty-http-10.0.22.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2024-6763">jetty-http</a></td>
</tr>
<tr>
@@ -244,7 +271,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>≤ 9.5</td>
<td>
json-path-2.8.0.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2023-51074">json-path</a></td>
</tr>
<tr>
@@ -253,16 +280,25 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>≤ 9.0</td>
<td>
commons-text-1.9.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2022-42889">commons-text</a></td>
</tr>
<tr>
<td>
+<a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39135">CVE-2022-39135</a>
</td>
+ <td>6.5-8.11.2, 9.0</td>
+ <td>
+ calcite-1.31.0.jar </td>
+ <td><span class="cdx-exploitable">exploitable</span></td>
+ <td><a href="/vex.html#cve-2022-39135">calcite</a></td>
+ </tr>
+ <tr>
+ <td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33980">CVE-2022-33980</a>
</td>
<td>≤ 9.0</td>
<td>
commons-configuration2-2.7.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2022-33980">commons-configuration2</a></td>
</tr>
<tr>
@@ -271,7 +307,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>≤ 9.0</td>
<td>
hadoop-common-3.2.2.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2022-25168">hadoop-common</a></td>
</tr>
<tr>
@@ -280,7 +316,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>7.4-8.11.1</td>
<td>
log4j-core-2.14.1.jar, log4j-core-2.16.0.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2021-45105">log4j-core</a></td>
</tr>
<tr>
@@ -289,7 +325,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>7.4-8.11.1</td>
<td>
log4j-core-2.14.1.jar, log4j-core-2.16.0.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2021-44832">log4j-core</a></td>
</tr>
<tr>
@@ -298,7 +334,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>≤ 8.x</td>
<td>
jdom-*.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2021-33813">jdom-*</a></td>
</tr>
<tr>
@@ -307,7 +343,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>7.3.0-8.x</td>
<td>
jetty-9.4.6 to 9.4.36 </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2020-27223">jetty-9.4.6 to 9.4.36</a></td>
</tr>
<tr>
@@ -316,7 +352,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>7.3.0-8.8.0</td>
<td>
jetty-9.4.0 to 9.4.34 </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2020-27218">jetty-9.4.0 to 9.4.34</a></td>
</tr>
<tr>
@@ -325,7 +361,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>8.1.0-8.x</td>
<td>
avatica-core-1.13.0.jar, calcite-core-1.18.0.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2020-13955">avatica-core</a></td>
</tr>
<tr>
@@ -334,7 +370,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>8.2-8.3</td>
<td>
netty-all-4.1.29.Final.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2019-16869">netty-all</a></td>
</tr>
<tr>
@@ -343,7 +379,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>7.7.0-8.2</td>
<td>
jetty-9.4.14 </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2019-10241">jetty</a></td>
</tr>
<tr>
@@ -352,7 +388,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>8.0.0-8.3.0</td>
<td>
commons-beanutils-1.9.3.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2019-10086">commons-beanutils</a></td>
</tr>
<tr>
@@ -361,7 +397,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>4.x-9.1</td>
<td>
slf4j-api-1.7.24.jar, jcl-over-slf4j-1.7.24.jar,
jul-to-slf4j-1.7.24.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2018-8088">slf4j-api</a></td>
</tr>
<tr>
@@ -370,7 +406,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>5.4.0-7.7.2, 8.0-8.3</td>
<td>
simple-xml-2.7.1.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2018-1471">simple-xml</a></td>
</tr>
<tr>
@@ -379,7 +415,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>7.3.1-7.5.0</td>
<td>
tika-core.1.17.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2018-1335">tika-core.1.17</a></td>
</tr>
<tr>
@@ -388,7 +424,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>5.4.0-8.x</td>
<td>
carrot2-guava-18.0.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2018-10237">carrot2-guava</a></td>
</tr>
<tr>
@@ -397,7 +433,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>4.6.0-8.x</td>
<td>
guava-*.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2018-10237-guava">guava-*</a></td>
</tr>
<tr>
@@ -406,7 +442,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>4.6.0-8.x</td>
<td>
dom4j-1.6.1.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2018-1000632">dom4j</a></td>
</tr>
<tr>
@@ -415,7 +451,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>4.6.0-7.6.0</td>
<td>
junit-4.10.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2018-1000056">junit</a></td>
</tr>
<tr>
@@ -424,7 +460,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>6.6.1-7.6.0</td>
<td>
hadoop-auth-2.7.4.jar, hadoop-hdfs-2.7.4.jar (all Hadoop)
</td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2017-15718">hadoop-auth</a></td>
</tr>
<tr>
@@ -433,7 +469,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>4.7.0-8.x</td>
<td>
jackson-databind-*.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2017-15095">jackson-databind-*</a></td>
</tr>
<tr>
@@ -442,7 +478,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>6.0.0-7.5.0</td>
<td>
icu4j-56.1.jar, icu4j-59.1.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2017-14952">icu4j</a></td>
</tr>
<tr>
@@ -451,7 +487,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>5.2.0-8.x</td>
<td>
org.restlet-2.3.0.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2017-14868">org.restlet</a></td>
</tr>
<tr>
@@ -460,7 +496,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>5.5.5, 6.2.0-9.10</td>
<td>
vorbis-java-tika-0.8.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2016-6809">vorbis-java-tika</a></td>
</tr>
<tr>
@@ -469,7 +505,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>6.6.2-8.x</td>
<td>
velocity-tools-2.0.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2016-1181">Apache Struts 1 CVEs via
velocity-tools transitive dependency</a></td>
</tr>
<tr>
@@ -478,7 +514,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>6.5.0-7.x</td>
<td>
protobuf-java-3.1.0.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2015-5237">protobuf-java</a></td>
</tr>
<tr>
@@ -487,7 +523,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>7.3.1</td>
<td>
lucene-analyzers-icu-7.3.1.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2014-7940">lucene-analyzers-icu</a></td>
</tr>
<tr>
@@ -496,7 +532,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>4.9.0-7.5.0</td>
<td>
commons-beanutils-1.8.3.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2014-0114">commons-beanutils</a></td>
</tr>
<tr>
@@ -505,7 +541,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>4.6.0-7.x</td>
<td>
commons-compress (only as part of Ant 1.8.2) </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2012-2098">commons-compress (only as part of
Ant 1.8.2)</a></td>
</tr>
<tr>
@@ -514,7 +550,7 @@ or contact <a
href="mailto:[email protected]">[email protected]</a>.</p>
<td>2.9-9.10</td>
<td>
xercesImpl-2.9.1.jar </td>
- <td>not affected</td>
+ <td><span class="cdx-not-affected">not affected</span></td>
<td><a href="/vex.html#cve-2012-0881">xercesImpl</a></td>
</tr>
</table>