This is an automated email from the ASF dual-hosted git repository.

github-actions[bot] pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/solr-site.git


The following commit(s) were added to refs/heads/asf-staging by this push:
     new bc3b5eecd Commit build products
bc3b5eecd is described below

commit bc3b5eecdfa6492432ae13390fb6184b85e42b96
Author: Build Pelican (action) <[email protected]>
AuthorDate: Sun Jun 21 18:53:09 2026 +0000

    Commit build products
---
 output/security-dependency-cves.html | 116 +++++++++++++++++++++++------------
 1 file changed, 76 insertions(+), 40 deletions(-)

diff --git a/output/security-dependency-cves.html 
b/output/security-dependency-cves.html
index a96bb706e..a483c2367 100644
--- a/output/security-dependency-cves.html
+++ b/output/security-dependency-cves.html
@@ -163,8 +163,8 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
   </div>
 
   <h2 id="cve-table">CVE Status for Dependencies <a class="headerlink" 
href="#cve-table" title="Permanent link">¶</a></h2>
-  <p>Below is a list of CVE vulnerabilities in Apache Solr dependencies and 
their applicability to Solr.
-     CVEs assessed as exploitable in Solr have their own advisory on the
+  <p>Below is a list of CVE vulnerabilities in Apache Solr dependencies and 
their applicability to Solr,
+     with the assessed state of each. CVEs assessed as exploitable in Solr 
also have their own advisory on the
      <a href="/security-news.html">security news page</a>.</p>
 
   <table>
@@ -177,11 +177,38 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     </tr>
     <tr>
       <td>
+<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42440";>CVE-2026-42440</a>   
   </td>
+      <td>< 10.1.0</td>
+      <td>
+          opennlp-tools-1.9.4.jar      </td>
+      <td><span class="cdx-exploitable">exploitable</span></td>
+      <td><a href="/vex.html#cve-2026-42440">Apache OpenNLP: Out-of-memory 
denial of service via crafted model file</a></td>
+    </tr>
+    <tr>
+      <td>
+<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42027";>CVE-2026-42027</a>   
   </td>
+      <td>< 10.1.0</td>
+      <td>
+          opennlp-tools-1.9.4.jar      </td>
+      <td><span class="cdx-exploitable">exploitable</span></td>
+      <td><a href="/vex.html#cve-2026-42027">Apache OpenNLP: Arbitrary class 
instantiation via model manifest</a></td>
+    </tr>
+    <tr>
+      <td>
+<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40682";>CVE-2026-40682</a>   
   </td>
+      <td>< 10.1.0</td>
+      <td>
+          opennlp-tools-1.9.4.jar      </td>
+      <td><span class="cdx-exploitable">exploitable</span></td>
+      <td><a href="/vex.html#cve-2026-40682">Apache OpenNLP: XXE in dictionary 
parsing</a></td>
+    </tr>
+    <tr>
+      <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34481";>CVE-2026-34481</a>   
   </td>
       <td>9.10.1, 10.0.0</td>
       <td>
           log4j-layout-template-json-2.25.3.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2026-34481">Apache Log4j JSON Template 
Layout: Invalid JSON for non-finite floating-point values</a></td>
     </tr>
     <tr>
@@ -190,7 +217,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>9.10.1, 10.0.0</td>
       <td>
           log4j-core-2.25.3.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2026-34480">Apache Log4j Core: Invalid XML 
output from XmlLayout</a></td>
     </tr>
     <tr>
@@ -199,7 +226,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>9.10.1, 10.0.0</td>
       <td>
           log4j-1.2-api-2.25.3.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2026-34479">Apache Log4j 1.x bridge: 
Malformed XML output from Log4j1XmlLayout</a></td>
     </tr>
     <tr>
@@ -208,7 +235,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>9.10.1, 10.0.0</td>
       <td>
           log4j-core-2.25.3.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2026-34478">Apache Log4j Core: Log injection 
via CRLF sequences in Rfc5424Layout</a></td>
     </tr>
     <tr>
@@ -217,7 +244,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>9.10.1, 10.0.0</td>
       <td>
           log4j-core-2.25.3.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2026-34477">Apache Log4j Core: TLS hostname 
verification silently ignored in Socket, SMTP and Syslog appenders</a></td>
     </tr>
     <tr>
@@ -226,7 +253,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>9.4.0-9.8.1</td>
       <td>
           zookeeper-3.9.0.jar,           zookeeper-3.9.1.jar,           
zookeeper-3.9.2.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2024-51504">Apache ZooKeeper: Authentication 
bypass with IP-based authentication in Admin Server</a></td>
     </tr>
     <tr>
@@ -235,7 +262,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>≤ 9.7</td>
       <td>
           jetty-http-10.0.22.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2024-6763">jetty-http</a></td>
     </tr>
     <tr>
@@ -244,7 +271,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>≤ 9.5</td>
       <td>
           json-path-2.8.0.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2023-51074">json-path</a></td>
     </tr>
     <tr>
@@ -253,16 +280,25 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>≤ 9.0</td>
       <td>
           commons-text-1.9.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2022-42889">commons-text</a></td>
     </tr>
     <tr>
       <td>
+<a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39135";>CVE-2022-39135</a>   
   </td>
+      <td>6.5-8.11.2, 9.0</td>
+      <td>
+          calcite-1.31.0.jar      </td>
+      <td><span class="cdx-exploitable">exploitable</span></td>
+      <td><a href="/vex.html#cve-2022-39135">calcite</a></td>
+    </tr>
+    <tr>
+      <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33980";>CVE-2022-33980</a>   
   </td>
       <td>≤ 9.0</td>
       <td>
           commons-configuration2-2.7.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2022-33980">commons-configuration2</a></td>
     </tr>
     <tr>
@@ -271,7 +307,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>≤ 9.0</td>
       <td>
           hadoop-common-3.2.2.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2022-25168">hadoop-common</a></td>
     </tr>
     <tr>
@@ -280,7 +316,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>7.4-8.11.1</td>
       <td>
           log4j-core-2.14.1.jar,           log4j-core-2.16.0.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2021-45105">log4j-core</a></td>
     </tr>
     <tr>
@@ -289,7 +325,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>7.4-8.11.1</td>
       <td>
           log4j-core-2.14.1.jar,           log4j-core-2.16.0.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2021-44832">log4j-core</a></td>
     </tr>
     <tr>
@@ -298,7 +334,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>≤ 8.x</td>
       <td>
           jdom-*.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2021-33813">jdom-*</a></td>
     </tr>
     <tr>
@@ -307,7 +343,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>7.3.0-8.x</td>
       <td>
           jetty-9.4.6 to 9.4.36      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2020-27223">jetty-9.4.6 to 9.4.36</a></td>
     </tr>
     <tr>
@@ -316,7 +352,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>7.3.0-8.8.0</td>
       <td>
           jetty-9.4.0 to 9.4.34      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2020-27218">jetty-9.4.0 to 9.4.34</a></td>
     </tr>
     <tr>
@@ -325,7 +361,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>8.1.0-8.x</td>
       <td>
           avatica-core-1.13.0.jar,           calcite-core-1.18.0.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2020-13955">avatica-core</a></td>
     </tr>
     <tr>
@@ -334,7 +370,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>8.2-8.3</td>
       <td>
           netty-all-4.1.29.Final.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2019-16869">netty-all</a></td>
     </tr>
     <tr>
@@ -343,7 +379,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>7.7.0-8.2</td>
       <td>
           jetty-9.4.14      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2019-10241">jetty</a></td>
     </tr>
     <tr>
@@ -352,7 +388,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>8.0.0-8.3.0</td>
       <td>
           commons-beanutils-1.9.3.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2019-10086">commons-beanutils</a></td>
     </tr>
     <tr>
@@ -361,7 +397,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>4.x-9.1</td>
       <td>
           slf4j-api-1.7.24.jar,           jcl-over-slf4j-1.7.24.jar,           
jul-to-slf4j-1.7.24.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2018-8088">slf4j-api</a></td>
     </tr>
     <tr>
@@ -370,7 +406,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>5.4.0-7.7.2, 8.0-8.3</td>
       <td>
           simple-xml-2.7.1.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2018-1471">simple-xml</a></td>
     </tr>
     <tr>
@@ -379,7 +415,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>7.3.1-7.5.0</td>
       <td>
           tika-core.1.17.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2018-1335">tika-core.1.17</a></td>
     </tr>
     <tr>
@@ -388,7 +424,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>5.4.0-8.x</td>
       <td>
           carrot2-guava-18.0.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2018-10237">carrot2-guava</a></td>
     </tr>
     <tr>
@@ -397,7 +433,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>4.6.0-8.x</td>
       <td>
           guava-*.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2018-10237-guava">guava-*</a></td>
     </tr>
     <tr>
@@ -406,7 +442,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>4.6.0-8.x</td>
       <td>
           dom4j-1.6.1.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2018-1000632">dom4j</a></td>
     </tr>
     <tr>
@@ -415,7 +451,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>4.6.0-7.6.0</td>
       <td>
           junit-4.10.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2018-1000056">junit</a></td>
     </tr>
     <tr>
@@ -424,7 +460,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>6.6.1-7.6.0</td>
       <td>
           hadoop-auth-2.7.4.jar,           hadoop-hdfs-2.7.4.jar (all Hadoop)  
    </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2017-15718">hadoop-auth</a></td>
     </tr>
     <tr>
@@ -433,7 +469,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>4.7.0-8.x</td>
       <td>
           jackson-databind-*.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2017-15095">jackson-databind-*</a></td>
     </tr>
     <tr>
@@ -442,7 +478,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>6.0.0-7.5.0</td>
       <td>
           icu4j-56.1.jar,           icu4j-59.1.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2017-14952">icu4j</a></td>
     </tr>
     <tr>
@@ -451,7 +487,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>5.2.0-8.x</td>
       <td>
           org.restlet-2.3.0.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2017-14868">org.restlet</a></td>
     </tr>
     <tr>
@@ -460,7 +496,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>5.5.5, 6.2.0-9.10</td>
       <td>
           vorbis-java-tika-0.8.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2016-6809">vorbis-java-tika</a></td>
     </tr>
     <tr>
@@ -469,7 +505,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>6.6.2-8.x</td>
       <td>
           velocity-tools-2.0.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2016-1181">Apache Struts 1 CVEs via 
velocity-tools transitive dependency</a></td>
     </tr>
     <tr>
@@ -478,7 +514,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>6.5.0-7.x</td>
       <td>
           protobuf-java-3.1.0.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2015-5237">protobuf-java</a></td>
     </tr>
     <tr>
@@ -487,7 +523,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>7.3.1</td>
       <td>
           lucene-analyzers-icu-7.3.1.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2014-7940">lucene-analyzers-icu</a></td>
     </tr>
     <tr>
@@ -496,7 +532,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>4.9.0-7.5.0</td>
       <td>
           commons-beanutils-1.8.3.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2014-0114">commons-beanutils</a></td>
     </tr>
     <tr>
@@ -505,7 +541,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>4.6.0-7.x</td>
       <td>
           commons-compress (only as part of Ant 1.8.2)      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2012-2098">commons-compress (only as part of 
Ant 1.8.2)</a></td>
     </tr>
     <tr>
@@ -514,7 +550,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
       <td>2.9-9.10</td>
       <td>
           xercesImpl-2.9.1.jar      </td>
-      <td>not affected</td>
+      <td><span class="cdx-not-affected">not affected</span></td>
       <td><a href="/vex.html#cve-2012-0881">xercesImpl</a></td>
     </tr>
   </table>

Reply via email to