This is an automated email from the ASF dual-hosted git repository.

github-actions[bot] pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/solr-site.git


The following commit(s) were added to refs/heads/asf-staging by this push:
     new 64488a66d Commit build products
64488a66d is described below

commit 64488a66dd0d4ba8b18abecc45b4d4f80d95106f
Author: Build Pelican (action) <[email protected]>
AuthorDate: Thu Aug 13 01:34:46 2026 +0000

    Commit build products
---
 output/feeds/all.atom.xml            |  32 +++-
 output/feeds/solr/vex.atom.xml       |  32 +++-
 output/security-dependency-cves.html |   8 +-
 output/solr.openvex.json             |  33 ++--
 output/solr.vex.json                 | 308 +++++++++++++++++------------------
 output/vex.html                      |  40 +++--
 6 files changed, 243 insertions(+), 210 deletions(-)

diff --git a/output/feeds/all.atom.xml b/output/feeds/all.atom.xml
index ca60fe072..77d32f7f2 100644
--- a/output/feeds/all.atom.xml
+++ b/output/feeds/all.atom.xml
@@ -17,10 +17,14 @@ avro &amp;lt; 1.11.3). Both require the application to feed 
attacker-controlled
   own internal machinery, driven by administrator-supplied configuration, not 
by untrusted request
   input.&lt;/li&gt;
 &lt;/ul&gt;
-&lt;p&gt;The affected range covers the 9.x line, where the optional Hadoop 
modules transitively carry Avro
-1.9.2; Solr's own code path never invokes it. A scanner surfaces this as 
&lt;code&gt;[email protected]&lt;/code&gt; because Avro is
-shaded inside &lt;code&gt;hadoop-client-runtime-3.4.0.jar&lt;/code&gt; in the 
&lt;code&gt;hdfs&lt;/code&gt; module (this is the form reported by
-SOLR-17900); it is the same non-reachable Hadoop transitive either 
way.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>jackson-core: memory disclosure via 
source snippet in JsonLocation error messages</title><link 
href="/cve-2025-49128.html" 
rel="alternate"/><published>2026-07-31T00:00:00+00:00</published><updated>2026-07-31T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2026-07-31:/cve-2025-49128.html</id><summary
 type="html">&lt;p [...]
+&lt;p&gt;The affected range covers Solr 9.0.0 – 9.10.1, where the optional 
Hadoop modules transitively carry a
+vulnerable Avro (1.7.7 in &lt;code&gt;hadoop-client-runtime&lt;/code&gt; 3.3.2 
– 3.3.6, then 1.9.2 in 3.4.0 – 3.4.1); Solr's
+own code path never invokes it. A scanner surfaces this as 
&lt;code&gt;[email protected]&lt;/code&gt; because Avro is shaded inside
+&lt;code&gt;hadoop-client-runtime&lt;/code&gt; in the 
&lt;code&gt;hdfs&lt;/code&gt; module (the form reported by SOLR-17900). Unlike 
the other
+Hadoop-shaded CVEs from SOLR-17900, Avro stayed vulnerable all the way through 
9.10.1: Solr 9.11
+(branch_9x) is the first fixed release, having upgraded to Hadoop 3.4.3, whose 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt;
+shades Avro 1.11.4 (past both the 1.11.3 and 1.11.4 fixes). Solr 10.x ships no 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt;.
+Either way it is the same non-reachable Hadoop 
transitive.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>jackson-core: memory disclosure via 
source snippet in JsonLocation error messages</title><link 
href="/cve-2025-49128.html" 
rel="alternate"/><published>2026-07-31T00:00:00+00:00</published><updated>2026-07-31T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2026-07-31:/cve-2025-49128.html</id><summary
 type="html">&lt;p&gt;CVE-2025- [...]
 includes in &lt;code&gt;JsonLocation&lt;/code&gt; (e.g. surfaced in 
parse-error messages). It affects jackson-core &amp;lt; 2.13.0.&lt;/p&gt;
 &lt;p&gt;Solr is &lt;strong&gt;not affected&lt;/strong&gt;. Solr's own 
jackson-core is 2.18.0 in current 9.x and 2.22.0 in 9.11 — both 
…&lt;/p&gt;</summary><content type="html">&lt;p&gt;CVE-2025-49128 can disclose 
adjacent buffer memory through the source snippet that jackson-core
 includes in &lt;code&gt;JsonLocation&lt;/code&gt; (e.g. surfaced in 
parse-error messages). It affects jackson-core &amp;lt; 2.13.0.&lt;/p&gt;
@@ -1542,8 +1546,10 @@ application parses attacker-supplied JOSE/JWT input with 
Nimbus.&lt;/p&gt;
 scanner flags (&lt;code&gt;[email protected]&lt;/code&gt;) is shaded inside 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt; in the optional
 &lt;code&gt;hdfs&lt;/code&gt; module and is only used by Hadoop's own internal 
auth machinery — Solr never routes an
 untrusted, externally-supplied JOSE object to it. The vulnerable parser is 
therefore not reached. The
-affected range spans the releases whose &lt;code&gt;hdfs&lt;/code&gt; module 
bundles the affected shaded Nimbus (Solr
-9.0.0 – 9.10.1); Solr 10.x ships no 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt;.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache James MIME4J: header injection 
when composing MIME messages</title><link href="/cve-2024-21742.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-21742.html</id><summary
 type="html">&lt;p&gt [...]
+affected range spans the releases whose &lt;code&gt;hdfs&lt;/code&gt; module 
bundles an affected shaded Nimbus — Solr
+9.0.0 – 9.9.0 (&lt;code&gt;hadoop-client-runtime&lt;/code&gt; 3.3.2 – 3.4.0, 
shading Nimbus ≤ 9.31). Solr 9.10.0 upgraded to
+Hadoop 3.4.1, whose &lt;code&gt;hadoop-client-runtime&lt;/code&gt; shades the 
fixed Nimbus 9.37.2, and Solr 10.x ships no
+&lt;code&gt;hadoop-client-runtime&lt;/code&gt;, so neither is 
affected.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache James MIME4J: header injection 
when composing MIME messages</title><link href="/cve-2024-21742.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-21742.html</id><summary
 type="html">&lt;p&gt;CVE-2024-21 [...]
 used to &lt;strong&gt;compose / write&lt;/strong&gt; MIME messages, improper 
input validation lets crafted field values inject
 unintended headers into the produced message. It affects 
&lt;code&gt;apache-mime4j&lt;/code&gt; before 0.8.10 (fixed in
 0.8.10), and is …&lt;/p&gt;</summary><content 
type="html">&lt;p&gt;CVE-2024-21742 (CVSS 5.3) is a header-injection issue in 
Apache James MIME4J: when the library is
@@ -1572,7 +1578,9 @@ where Hadoop may use it for name resolution. Solr uses 
the HDFS module only as a
 connects to operator-configured HDFS NameNode/DataNode hosts, not 
attacker-controlled names, and it
 does not rely on dnsjava's DNSSEC validation to make any security decision. 
The vulnerable resolver
 path is therefore not reached. The affected range spans the releases whose 
&lt;code&gt;hdfs&lt;/code&gt; module bundles an
-affected shaded dnsjava (Solr 9.0.0 – 9.10.1); Solr 10.x ships no 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt;.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache Commons Compress: 
OutOfMemoryError unpacking a broken Pack200 file</title><link 
href="/cve-2024-26308.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 Developers</name></author><id>tag:None,2025-09-07:/cve-2024-26308.h [...]
+affected shaded dnsjava — Solr 9.0.0 – 9.9.0 
(&lt;code&gt;hadoop-client-runtime&lt;/code&gt; 3.3.2 – 3.4.0, shading dnsjava
+≤ 3.4.0). Solr 9.10.0 upgraded to Hadoop 3.4.1, whose 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt; shades the fixed dnsjava
+3.6.1, and Solr 10.x ships no &lt;code&gt;hadoop-client-runtime&lt;/code&gt;, 
so neither is affected.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache Commons Compress: 
OutOfMemoryError unpacking a broken Pack200 file</title><link 
href="/cve-2024-26308.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-26308.html</id><sum 
[...]
 malformed &lt;strong&gt;Pack200&lt;/strong&gt; 
(&lt;code&gt;.pack&lt;/code&gt;/&lt;code&gt;.pack.gz&lt;/code&gt;) stream can 
allocate excessive memory and throw
 &lt;code&gt;OutOfMemoryError&lt;/code&gt; (affects 1.21 through 1.25.0, fixed 
in 1.26.0). It is reachable only when an
 application uses Commons Compress to …&lt;/p&gt;</summary><content 
type="html">&lt;p&gt;CVE-2024-26308 (CVSS 6.7) is a denial-of-service issue in 
Apache Commons Compress: unpacking a
@@ -1585,7 +1593,10 @@ format) is not part of any Solr request path. The 
affected &lt;code&gt;commons-c
 module; Solr's HDFS-client usage does not feed untrusted Pack200 input to it, 
and Solr's own use of
 Commons Compress elsewhere does not invoke the Pack200 unpacker. The 
vulnerable code path is therefore
 not reached. The affected range spans the releases whose 
&lt;code&gt;hdfs&lt;/code&gt; module bundles an affected shaded
-commons-compress (Solr 9.0.0 – 9.10.1); Solr 10.x ships no 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt;.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache Commons Configuration: 
StackOverflowError in list-delimiter handling</title><link 
href="/cve-2024-29131.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 Developers</name></author><id>tag:None,2025-09-07:/cve-2024-29131.html</ [...]
+commons-compress — Solr 9.0.0 – 9.9.0 
(&lt;code&gt;hadoop-client-runtime&lt;/code&gt; 3.3.2 – 3.4.0, shading 
commons-compress
+≤ 1.24.0; the standalone copy in the &lt;code&gt;extraction&lt;/code&gt; 
module was already ≥ 1.26.0 by 9.7.0). Solr 9.10.0
+upgraded to Hadoop 3.4.1, whose &lt;code&gt;hadoop-client-runtime&lt;/code&gt; 
shades the fixed commons-compress 1.26.1, and
+Solr 10.x ships no &lt;code&gt;hadoop-client-runtime&lt;/code&gt;, so neither 
is affected.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache Commons Configuration: 
StackOverflowError in list-delimiter handling</title><link 
href="/cve-2024-29131.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-29131.html</id><summary
 type [...]
 Configuration's list-delimiter handling — 
&lt;code&gt;AbstractListDelimiterHandler.flattenIterator(...)&lt;/code&gt; and
 &lt;code&gt;ListDelimiterHandler.flatten(Object, int)&lt;/code&gt; 
respectively — when a configuration contains a cyclic
 reference (both affect 2.0 through 2.10.0, fixed in 2.10.1).&lt;/p&gt;
@@ -1600,7 +1611,10 @@ integration — both the standalone copy in the 
&lt;code&gt;hadoop-auth&lt;/code
 path feeds attacker-controlled configuration to Commons Configuration, so the 
recursive list-delimiter
 parser cannot be driven by an adversary. This matches the existing assessment 
of the other Commons
 Configuration CVEs (CVE-2022-33980, CVE-2026-45205). The affected range spans 
the releases whose
-Hadoop modules carry an affected commons-configuration2 (Solr 9.0.0 – 
9.10.1).&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache POI: improper input validation 
parsing OOXML files</title><link href="/cve-2025-31672.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2025-31672.html</id><summary
 type="html">&lt;p&gt;CVE-2025-3167 [...]
+Hadoop modules carry an affected commons-configuration2 — Solr 9.0.0 – 9.9.0 
(&lt;code&gt;hadoop-client-runtime&lt;/code&gt;
+3.3.2 – 3.4.0 shades commons-configuration2 ≤ 2.8.0; the standalone 
&lt;code&gt;hadoop-auth&lt;/code&gt; copy was already
+≥ 2.10.1, at 2.11.0, by 9.7.0). Solr 9.10.0 upgraded to Hadoop 3.4.1, whose 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt;
+shades the fixed commons-configuration2 2.10.1, so 9.10.x onward is not 
affected.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache POI: improper input validation 
parsing OOXML files</title><link href="/cve-2025-31672.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2025-31672.html</id><summary
 type="html">&lt;p&gt;CVE-2025-3 [...]
 a crafted OOXML file (&lt;code&gt;.xlsx&lt;/code&gt;, 
&lt;code&gt;.docx&lt;/code&gt;, etc.) can cause 
&lt;code&gt;poi-ooxml&lt;/code&gt; to read unexpected data or consume
 excessive resources. It affects all &lt;code&gt;poi-ooxml&lt;/code&gt; 
releases before 5.4.0 (fixed in 5.4.0). Solr bundles
 an affected …&lt;/p&gt;</summary><content type="html">&lt;p&gt;CVE-2025-31672 
(CVSS 6.9) is an improper-input-validation issue in Apache POI's OOXML parser: 
parsing
diff --git a/output/feeds/solr/vex.atom.xml b/output/feeds/solr/vex.atom.xml
index 6ba853bd0..050295bf0 100644
--- a/output/feeds/solr/vex.atom.xml
+++ b/output/feeds/solr/vex.atom.xml
@@ -17,10 +17,14 @@ avro &amp;lt; 1.11.3). Both require the application to feed 
attacker-controlled
   own internal machinery, driven by administrator-supplied configuration, not 
by untrusted request
   input.&lt;/li&gt;
 &lt;/ul&gt;
-&lt;p&gt;The affected range covers the 9.x line, where the optional Hadoop 
modules transitively carry Avro
-1.9.2; Solr's own code path never invokes it. A scanner surfaces this as 
&lt;code&gt;[email protected]&lt;/code&gt; because Avro is
-shaded inside &lt;code&gt;hadoop-client-runtime-3.4.0.jar&lt;/code&gt; in the 
&lt;code&gt;hdfs&lt;/code&gt; module (this is the form reported by
-SOLR-17900); it is the same non-reachable Hadoop transitive either 
way.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>jackson-core: memory disclosure via 
source snippet in JsonLocation error messages</title><link 
href="/cve-2025-49128.html" 
rel="alternate"/><published>2026-07-31T00:00:00+00:00</published><updated>2026-07-31T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2026-07-31:/cve-2025-49128.html</id><summary
 type="html">&lt;p [...]
+&lt;p&gt;The affected range covers Solr 9.0.0 – 9.10.1, where the optional 
Hadoop modules transitively carry a
+vulnerable Avro (1.7.7 in &lt;code&gt;hadoop-client-runtime&lt;/code&gt; 3.3.2 
– 3.3.6, then 1.9.2 in 3.4.0 – 3.4.1); Solr's
+own code path never invokes it. A scanner surfaces this as 
&lt;code&gt;[email protected]&lt;/code&gt; because Avro is shaded inside
+&lt;code&gt;hadoop-client-runtime&lt;/code&gt; in the 
&lt;code&gt;hdfs&lt;/code&gt; module (the form reported by SOLR-17900). Unlike 
the other
+Hadoop-shaded CVEs from SOLR-17900, Avro stayed vulnerable all the way through 
9.10.1: Solr 9.11
+(branch_9x) is the first fixed release, having upgraded to Hadoop 3.4.3, whose 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt;
+shades Avro 1.11.4 (past both the 1.11.3 and 1.11.4 fixes). Solr 10.x ships no 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt;.
+Either way it is the same non-reachable Hadoop 
transitive.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>jackson-core: memory disclosure via 
source snippet in JsonLocation error messages</title><link 
href="/cve-2025-49128.html" 
rel="alternate"/><published>2026-07-31T00:00:00+00:00</published><updated>2026-07-31T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2026-07-31:/cve-2025-49128.html</id><summary
 type="html">&lt;p&gt;CVE-2025- [...]
 includes in &lt;code&gt;JsonLocation&lt;/code&gt; (e.g. surfaced in 
parse-error messages). It affects jackson-core &amp;lt; 2.13.0.&lt;/p&gt;
 &lt;p&gt;Solr is &lt;strong&gt;not affected&lt;/strong&gt;. Solr's own 
jackson-core is 2.18.0 in current 9.x and 2.22.0 in 9.11 — both 
…&lt;/p&gt;</summary><content type="html">&lt;p&gt;CVE-2025-49128 can disclose 
adjacent buffer memory through the source snippet that jackson-core
 includes in &lt;code&gt;JsonLocation&lt;/code&gt; (e.g. surfaced in 
parse-error messages). It affects jackson-core &amp;lt; 2.13.0.&lt;/p&gt;
@@ -1310,8 +1314,10 @@ application parses attacker-supplied JOSE/JWT input with 
Nimbus.&lt;/p&gt;
 scanner flags (&lt;code&gt;[email protected]&lt;/code&gt;) is shaded inside 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt; in the optional
 &lt;code&gt;hdfs&lt;/code&gt; module and is only used by Hadoop's own internal 
auth machinery — Solr never routes an
 untrusted, externally-supplied JOSE object to it. The vulnerable parser is 
therefore not reached. The
-affected range spans the releases whose &lt;code&gt;hdfs&lt;/code&gt; module 
bundles the affected shaded Nimbus (Solr
-9.0.0 – 9.10.1); Solr 10.x ships no 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt;.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache James MIME4J: header injection 
when composing MIME messages</title><link href="/cve-2024-21742.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-21742.html</id><summary
 type="html">&lt;p&gt [...]
+affected range spans the releases whose &lt;code&gt;hdfs&lt;/code&gt; module 
bundles an affected shaded Nimbus — Solr
+9.0.0 – 9.9.0 (&lt;code&gt;hadoop-client-runtime&lt;/code&gt; 3.3.2 – 3.4.0, 
shading Nimbus ≤ 9.31). Solr 9.10.0 upgraded to
+Hadoop 3.4.1, whose &lt;code&gt;hadoop-client-runtime&lt;/code&gt; shades the 
fixed Nimbus 9.37.2, and Solr 10.x ships no
+&lt;code&gt;hadoop-client-runtime&lt;/code&gt;, so neither is 
affected.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache James MIME4J: header injection 
when composing MIME messages</title><link href="/cve-2024-21742.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-21742.html</id><summary
 type="html">&lt;p&gt;CVE-2024-21 [...]
 used to &lt;strong&gt;compose / write&lt;/strong&gt; MIME messages, improper 
input validation lets crafted field values inject
 unintended headers into the produced message. It affects 
&lt;code&gt;apache-mime4j&lt;/code&gt; before 0.8.10 (fixed in
 0.8.10), and is …&lt;/p&gt;</summary><content 
type="html">&lt;p&gt;CVE-2024-21742 (CVSS 5.3) is a header-injection issue in 
Apache James MIME4J: when the library is
@@ -1340,7 +1346,9 @@ where Hadoop may use it for name resolution. Solr uses 
the HDFS module only as a
 connects to operator-configured HDFS NameNode/DataNode hosts, not 
attacker-controlled names, and it
 does not rely on dnsjava's DNSSEC validation to make any security decision. 
The vulnerable resolver
 path is therefore not reached. The affected range spans the releases whose 
&lt;code&gt;hdfs&lt;/code&gt; module bundles an
-affected shaded dnsjava (Solr 9.0.0 – 9.10.1); Solr 10.x ships no 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt;.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache Commons Compress: 
OutOfMemoryError unpacking a broken Pack200 file</title><link 
href="/cve-2024-26308.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 Developers</name></author><id>tag:None,2025-09-07:/cve-2024-26308.h [...]
+affected shaded dnsjava — Solr 9.0.0 – 9.9.0 
(&lt;code&gt;hadoop-client-runtime&lt;/code&gt; 3.3.2 – 3.4.0, shading dnsjava
+≤ 3.4.0). Solr 9.10.0 upgraded to Hadoop 3.4.1, whose 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt; shades the fixed dnsjava
+3.6.1, and Solr 10.x ships no &lt;code&gt;hadoop-client-runtime&lt;/code&gt;, 
so neither is affected.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache Commons Compress: 
OutOfMemoryError unpacking a broken Pack200 file</title><link 
href="/cve-2024-26308.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-26308.html</id><sum 
[...]
 malformed &lt;strong&gt;Pack200&lt;/strong&gt; 
(&lt;code&gt;.pack&lt;/code&gt;/&lt;code&gt;.pack.gz&lt;/code&gt;) stream can 
allocate excessive memory and throw
 &lt;code&gt;OutOfMemoryError&lt;/code&gt; (affects 1.21 through 1.25.0, fixed 
in 1.26.0). It is reachable only when an
 application uses Commons Compress to …&lt;/p&gt;</summary><content 
type="html">&lt;p&gt;CVE-2024-26308 (CVSS 6.7) is a denial-of-service issue in 
Apache Commons Compress: unpacking a
@@ -1353,7 +1361,10 @@ format) is not part of any Solr request path. The 
affected &lt;code&gt;commons-c
 module; Solr's HDFS-client usage does not feed untrusted Pack200 input to it, 
and Solr's own use of
 Commons Compress elsewhere does not invoke the Pack200 unpacker. The 
vulnerable code path is therefore
 not reached. The affected range spans the releases whose 
&lt;code&gt;hdfs&lt;/code&gt; module bundles an affected shaded
-commons-compress (Solr 9.0.0 – 9.10.1); Solr 10.x ships no 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt;.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache Commons Configuration: 
StackOverflowError in list-delimiter handling</title><link 
href="/cve-2024-29131.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 Developers</name></author><id>tag:None,2025-09-07:/cve-2024-29131.html</ [...]
+commons-compress — Solr 9.0.0 – 9.9.0 
(&lt;code&gt;hadoop-client-runtime&lt;/code&gt; 3.3.2 – 3.4.0, shading 
commons-compress
+≤ 1.24.0; the standalone copy in the &lt;code&gt;extraction&lt;/code&gt; 
module was already ≥ 1.26.0 by 9.7.0). Solr 9.10.0
+upgraded to Hadoop 3.4.1, whose &lt;code&gt;hadoop-client-runtime&lt;/code&gt; 
shades the fixed commons-compress 1.26.1, and
+Solr 10.x ships no &lt;code&gt;hadoop-client-runtime&lt;/code&gt;, so neither 
is affected.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache Commons Configuration: 
StackOverflowError in list-delimiter handling</title><link 
href="/cve-2024-29131.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2024-29131.html</id><summary
 type [...]
 Configuration's list-delimiter handling — 
&lt;code&gt;AbstractListDelimiterHandler.flattenIterator(...)&lt;/code&gt; and
 &lt;code&gt;ListDelimiterHandler.flatten(Object, int)&lt;/code&gt; 
respectively — when a configuration contains a cyclic
 reference (both affect 2.0 through 2.10.0, fixed in 2.10.1).&lt;/p&gt;
@@ -1368,7 +1379,10 @@ integration — both the standalone copy in the 
&lt;code&gt;hadoop-auth&lt;/code
 path feeds attacker-controlled configuration to Commons Configuration, so the 
recursive list-delimiter
 parser cannot be driven by an adversary. This matches the existing assessment 
of the other Commons
 Configuration CVEs (CVE-2022-33980, CVE-2026-45205). The affected range spans 
the releases whose
-Hadoop modules carry an affected commons-configuration2 (Solr 9.0.0 – 
9.10.1).&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache POI: improper input validation 
parsing OOXML files</title><link href="/cve-2025-31672.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2025-31672.html</id><summary
 type="html">&lt;p&gt;CVE-2025-3167 [...]
+Hadoop modules carry an affected commons-configuration2 — Solr 9.0.0 – 9.9.0 
(&lt;code&gt;hadoop-client-runtime&lt;/code&gt;
+3.3.2 – 3.4.0 shades commons-configuration2 ≤ 2.8.0; the standalone 
&lt;code&gt;hadoop-auth&lt;/code&gt; copy was already
+≥ 2.10.1, at 2.11.0, by 9.7.0). Solr 9.10.0 upgraded to Hadoop 3.4.1, whose 
&lt;code&gt;hadoop-client-runtime&lt;/code&gt;
+shades the fixed commons-configuration2 2.10.1, so 9.10.x onward is not 
affected.&lt;/p&gt;</content><category 
term="solr/vex"/></entry><entry><title>Apache POI: improper input validation 
parsing OOXML files</title><link href="/cve-2025-31672.html" 
rel="alternate"/><published>2025-09-07T00:00:00+00:00</published><updated>2025-09-07T00:00:00+00:00</updated><author><name>Solr
 
Developers</name></author><id>tag:None,2025-09-07:/cve-2025-31672.html</id><summary
 type="html">&lt;p&gt;CVE-2025-3 [...]
 a crafted OOXML file (&lt;code&gt;.xlsx&lt;/code&gt;, 
&lt;code&gt;.docx&lt;/code&gt;, etc.) can cause 
&lt;code&gt;poi-ooxml&lt;/code&gt; to read unexpected data or consume
 excessive resources. It affects all &lt;code&gt;poi-ooxml&lt;/code&gt; 
releases before 5.4.0 (fixed in 5.4.0). Solr bundles
 an affected …&lt;/p&gt;</summary><content type="html">&lt;p&gt;CVE-2025-31672 
(CVSS 6.9) is an improper-input-validation issue in Apache POI's OOXML parser: 
parsing
diff --git a/output/security-dependency-cves.html 
b/output/security-dependency-cves.html
index 655040865..7d8b3831c 100644
--- a/output/security-dependency-cves.html
+++ b/output/security-dependency-cves.html
@@ -633,7 +633,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29131";>CVE-2024-29131</a>, 
<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29133";>CVE-2024-29133</a>    
  </td>
-      <td>9.0.0-9.10.1</td>
+      <td>9.0.0-9.9.0</td>
       <td>
           commons-configuration2-2.8.0.jar      </td>
       <td><span class="cdx-not-affected">not affected</span></td>
@@ -642,7 +642,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26308";>CVE-2024-26308</a>   
   </td>
-      <td>9.0.0-9.10.1</td>
+      <td>9.0.0-9.9.0</td>
       <td>
           commons-compress-1.24.0.jar      </td>
       <td><span class="cdx-not-affected">not affected</span></td>
@@ -651,7 +651,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25638";>CVE-2024-25638</a>   
   </td>
-      <td>9.0.0-9.10.1</td>
+      <td>9.0.0-9.9.0</td>
       <td>
           dnsjava-3.4.0.jar      </td>
       <td><span class="cdx-not-affected">not affected</span></td>
@@ -669,7 +669,7 @@ or contact <a 
href="mailto:[email protected]";>[email protected]</a>.</p>
     <tr>
       <td>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52428";>CVE-2023-52428</a>   
   </td>
-      <td>9.0.0-9.10.1</td>
+      <td>9.0.0-9.9.0</td>
       <td>
           nimbus-jose-jwt-9.31.jar      </td>
       <td><span class="cdx-not-affected">not affected</span></td>
diff --git a/output/solr.openvex.json b/output/solr.openvex.json
index 7824993cb..74e33ae8d 100644
--- a/output/solr.openvex.json
+++ b/output/solr.openvex.json
@@ -1616,8 +1616,8 @@
       "status": "not_affected",
       "timestamp": "2025-09-07T00:00:00Z",
       "justification": "vulnerable_code_not_in_execute_path",
-      "impact_statement": "CVE-2023-52428 (CVSS 8.7) is a denial-of-service 
issue in Nimbus JOSE + JWT: parsing a crafted JOSE\nobject (for example a 
PBES2-encrypted JWE with a huge `p2c` iteration count, or a large 
deeply-nested\nstructure) can consume excessive resources (fixed in 9.37.2). It 
is only reachable when an\napplication parses attacker-supplied JOSE/JWT input 
with Nimbus.\n\nSolr is **not affected**. Solr's own JWT authentication (the 
optional `jwt-auth` module,\n`JWTAuthPlu [...]
-      "status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
+      "impact_statement": "CVE-2023-52428 (CVSS 8.7) is a denial-of-service 
issue in Nimbus JOSE + JWT: parsing a crafted JOSE\nobject (for example a 
PBES2-encrypted JWE with a huge `p2c` iteration count, or a large 
deeply-nested\nstructure) can consume excessive resources (fixed in 9.37.2). It 
is only reachable when an\napplication parses attacker-supplied JOSE/JWT input 
with Nimbus.\n\nSolr is **not affected**. Solr's own JWT authentication (the 
optional `jwt-auth` module,\n`JWTAuthPlu [...]
+      "status_notes": "Affected Apache Solr versions: 9.0.0-9.9.0."
     },
     {
       "vulnerability": {
@@ -1661,8 +1661,8 @@
       "status": "not_affected",
       "timestamp": "2025-09-07T00:00:00Z",
       "justification": "vulnerable_code_not_in_execute_path",
-      "impact_statement": "CVE-2024-25638 (CVSS 7.0) is a DNSSEC-validation 
bypass in dnsjava: a resolver relying on dnsjava to\nvalidate DNSSEC could be 
tricked into accepting spoofed records (affects dnsjava < 3.6.0). It 
matters\nonly for an application that uses dnsjava as its resolver and relies 
on its DNSSEC validation for a\nsecurity decision.\n\nSolr is **not affected**. 
dnsjava is not a Solr dependency in its own right \u2014 it is shaded 
inside\n`hadoop-client-runtime` (reported [...]
-      "status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
+      "impact_statement": "CVE-2024-25638 (CVSS 7.0) is a DNSSEC-validation 
bypass in dnsjava: a resolver relying on dnsjava to\nvalidate DNSSEC could be 
tricked into accepting spoofed records (affects dnsjava < 3.6.0). It 
matters\nonly for an application that uses dnsjava as its resolver and relies 
on its DNSSEC validation for a\nsecurity decision.\n\nSolr is **not affected**. 
dnsjava is not a Solr dependency in its own right \u2014 it is shaded 
inside\n`hadoop-client-runtime` (reported [...]
+      "status_notes": "Affected Apache Solr versions: 9.0.0-9.9.0."
     },
     {
       "vulnerability": {
@@ -1686,16 +1686,13 @@
         },
         {
           "@id": "pkg:maven/org.apache.commons/[email protected]"
-        },
-        {
-          "@id": "pkg:maven/org.apache.commons/[email protected]"
         }
       ],
       "status": "not_affected",
       "timestamp": "2025-09-07T00:00:00Z",
       "justification": "vulnerable_code_not_in_execute_path",
-      "impact_statement": "CVE-2024-26308 (CVSS 6.7) is a denial-of-service 
issue in Apache Commons Compress: unpacking a\nmalformed **Pack200** 
(`.pack`/`.pack.gz`) stream can allocate excessive memory and 
throw\n`OutOfMemoryError` (affects 1.21 through 1.25.0, fixed in 1.26.0). It is 
reachable only when an\napplication uses Commons Compress to unpack an 
attacker-supplied Pack200 archive.\n\nSolr is **not affected**. Solr never 
unpacks Pack200 archives \u2014 Pack200 (a legacy JAR-compr [...]
-      "status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
+      "impact_statement": "CVE-2024-26308 (CVSS 6.7) is a denial-of-service 
issue in Apache Commons Compress: unpacking a\nmalformed **Pack200** 
(`.pack`/`.pack.gz`) stream can allocate excessive memory and 
throw\n`OutOfMemoryError` (affects 1.21 through 1.25.0, fixed in 1.26.0). It is 
reachable only when an\napplication uses Commons Compress to unpack an 
attacker-supplied Pack200 archive.\n\nSolr is **not affected**. Solr never 
unpacks Pack200 archives \u2014 Pack200 (a legacy JAR-compr [...]
+      "status_notes": "Affected Apache Solr versions: 9.0.0-9.9.0."
     },
     {
       "vulnerability": {
@@ -1708,9 +1705,6 @@
         {
           "@id": "pkg:maven/org.apache.commons/[email protected]"
         },
-        {
-          "@id": "pkg:maven/org.apache.commons/[email protected]"
-        },
         {
           "@id": "pkg:maven/org.apache.commons/[email protected]"
         },
@@ -1724,8 +1718,8 @@
       "status": "not_affected",
       "timestamp": "2025-09-07T00:00:00Z",
       "justification": "vulnerable_code_not_in_execute_path",
-      "impact_statement": "CVE-2024-29131 and CVE-2024-29133 are 
denial-of-service issues (StackOverflowError) in Apache 
Commons\nConfiguration's list-delimiter handling \u2014 
`AbstractListDelimiterHandler.flattenIterator(...)` 
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a 
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0, 
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses 
`commons-configuration2` only through its optional Had [...]
-      "status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
+      "impact_statement": "CVE-2024-29131 and CVE-2024-29133 are 
denial-of-service issues (StackOverflowError) in Apache 
Commons\nConfiguration's list-delimiter handling \u2014 
`AbstractListDelimiterHandler.flattenIterator(...)` 
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a 
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0, 
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses 
`commons-configuration2` only through its optional Had [...]
+      "status_notes": "Affected Apache Solr versions: 9.0.0-9.9.0."
     },
     {
       "vulnerability": {
@@ -1738,9 +1732,6 @@
         {
           "@id": "pkg:maven/org.apache.commons/[email protected]"
         },
-        {
-          "@id": "pkg:maven/org.apache.commons/[email protected]"
-        },
         {
           "@id": "pkg:maven/org.apache.commons/[email protected]"
         },
@@ -1754,8 +1745,8 @@
       "status": "not_affected",
       "timestamp": "2025-09-07T00:00:00Z",
       "justification": "vulnerable_code_not_in_execute_path",
-      "impact_statement": "CVE-2024-29131 and CVE-2024-29133 are 
denial-of-service issues (StackOverflowError) in Apache 
Commons\nConfiguration's list-delimiter handling \u2014 
`AbstractListDelimiterHandler.flattenIterator(...)` 
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a 
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0, 
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses 
`commons-configuration2` only through its optional Had [...]
-      "status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
+      "impact_statement": "CVE-2024-29131 and CVE-2024-29133 are 
denial-of-service issues (StackOverflowError) in Apache 
Commons\nConfiguration's list-delimiter handling \u2014 
`AbstractListDelimiterHandler.flattenIterator(...)` 
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a 
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0, 
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses 
`commons-configuration2` only through its optional Had [...]
+      "status_notes": "Affected Apache Solr versions: 9.0.0-9.9.0."
     },
     {
       "vulnerability": {
@@ -2971,7 +2962,7 @@
       "status": "not_affected",
       "timestamp": "2026-07-31T00:00:00Z",
       "justification": "vulnerable_code_not_in_execute_path",
-      "impact_statement": "CVE-2024-47561 (critical) is an 
arbitrary-code-execution issue in the Apache Avro Java SDK: parsing\nan 
attacker-controlled Avro **schema** can instantiate arbitrary classes (affects 
avro < 1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when 
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require 
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is 
**not affected**:\n\n* **Solr does not use Apache Avro. [...]
+      "impact_statement": "CVE-2024-47561 (critical) is an 
arbitrary-code-execution issue in the Apache Avro Java SDK: parsing\nan 
attacker-controlled Avro **schema** can instantiate arbitrary classes (affects 
avro < 1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when 
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require 
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is 
**not affected**:\n\n* **Solr does not use Apache Avro. [...]
       "status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
     },
     {
@@ -2986,7 +2977,7 @@
       "status": "not_affected",
       "timestamp": "2026-07-31T00:00:00Z",
       "justification": "vulnerable_code_not_in_execute_path",
-      "impact_statement": "CVE-2024-47561 (critical) is an 
arbitrary-code-execution issue in the Apache Avro Java SDK: parsing\nan 
attacker-controlled Avro **schema** can instantiate arbitrary classes (affects 
avro < 1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when 
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require 
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is 
**not affected**:\n\n* **Solr does not use Apache Avro. [...]
+      "impact_statement": "CVE-2024-47561 (critical) is an 
arbitrary-code-execution issue in the Apache Avro Java SDK: parsing\nan 
attacker-controlled Avro **schema** can instantiate arbitrary classes (affects 
avro < 1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when 
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require 
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is 
**not affected**:\n\n* **Solr does not use Apache Avro. [...]
       "status_notes": "Affected Apache Solr versions: 9.0.0-9.10.1."
     },
     {
diff --git a/output/solr.vex.json b/output/solr.vex.json
index 3b376bfce..80c3d96fe 100644
--- a/output/solr.vex.json
+++ b/output/solr.vex.json
@@ -7,7 +7,7 @@
       "name": "solr",
       "version": "SNAPSHOT",
       "type": "application",
-      "bom-ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+      "bom-ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
     }
   },
   "vulnerabilities": [
@@ -23,7 +23,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -39,7 +39,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -55,7 +55,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -71,7 +71,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -87,7 +87,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -103,7 +103,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -119,7 +119,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -135,7 +135,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -151,7 +151,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -167,7 +167,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -183,7 +183,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -199,7 +199,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -215,7 +215,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -231,7 +231,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -247,7 +247,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -263,7 +263,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -279,7 +279,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -295,7 +295,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -311,7 +311,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -327,7 +327,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -343,7 +343,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -359,7 +359,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -375,7 +375,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -391,7 +391,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -407,7 +407,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -423,7 +423,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -439,7 +439,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -455,7 +455,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -471,7 +471,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -487,7 +487,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -503,7 +503,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -519,7 +519,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -535,7 +535,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -551,7 +551,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -567,7 +567,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -583,7 +583,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -599,7 +599,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -615,7 +615,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -631,7 +631,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -647,7 +647,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -663,7 +663,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -679,7 +679,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -695,7 +695,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -711,7 +711,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -727,7 +727,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -743,7 +743,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -759,7 +759,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -775,7 +775,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -791,7 +791,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -807,7 +807,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -823,7 +823,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -839,7 +839,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -855,7 +855,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -871,7 +871,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -887,7 +887,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -903,7 +903,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -919,7 +919,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -935,7 +935,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -951,7 +951,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -970,7 +970,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -986,7 +986,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1002,7 +1002,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1018,7 +1018,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1037,7 +1037,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1053,7 +1053,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1070,7 +1070,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1087,7 +1087,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1104,7 +1104,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1121,7 +1121,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1138,7 +1138,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1155,7 +1155,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1172,7 +1172,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1185,11 +1185,11 @@
       "analysis": {
         "state": "not_affected",
         "justification": "code_not_reachable",
-        "detail": "CVE-2023-52428 (CVSS 8.7) is a denial-of-service issue in 
Nimbus JOSE + JWT: parsing a crafted JOSE\nobject (for example a 
PBES2-encrypted JWE with a huge `p2c` iteration count, or a large 
deeply-nested\nstructure) can consume excessive resources (fixed in 9.37.2). It 
is only reachable when an\napplication parses attacker-supplied JOSE/JWT input 
with Nimbus.\n\nSolr is **not affected**. Solr's own JWT authentication (the 
optional `jwt-auth` module,\n`JWTAuthPlugin`) pa [...]
+        "detail": "CVE-2023-52428 (CVSS 8.7) is a denial-of-service issue in 
Nimbus JOSE + JWT: parsing a crafted JOSE\nobject (for example a 
PBES2-encrypted JWE with a huge `p2c` iteration count, or a large 
deeply-nested\nstructure) can consume excessive resources (fixed in 9.37.2). It 
is only reachable when an\napplication parses attacker-supplied JOSE/JWT input 
with Nimbus.\n\nSolr is **not affected**. Solr's own JWT authentication (the 
optional `jwt-auth` module,\n`JWTAuthPlugin`) pa [...]
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1206,7 +1206,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1219,11 +1219,11 @@
       "analysis": {
         "state": "not_affected",
         "justification": "code_not_reachable",
-        "detail": "CVE-2024-25638 (CVSS 7.0) is a DNSSEC-validation bypass in 
dnsjava: a resolver relying on dnsjava to\nvalidate DNSSEC could be tricked 
into accepting spoofed records (affects dnsjava < 3.6.0). It matters\nonly for 
an application that uses dnsjava as its resolver and relies on its DNSSEC 
validation for a\nsecurity decision.\n\nSolr is **not affected**. dnsjava is 
not a Solr dependency in its own right \u2014 it is shaded 
inside\n`hadoop-client-runtime` (reported by scan [...]
+        "detail": "CVE-2024-25638 (CVSS 7.0) is a DNSSEC-validation bypass in 
dnsjava: a resolver relying on dnsjava to\nvalidate DNSSEC could be tricked 
into accepting spoofed records (affects dnsjava < 3.6.0). It matters\nonly for 
an application that uses dnsjava as its resolver and relies on its DNSSEC 
validation for a\nsecurity decision.\n\nSolr is **not affected**. dnsjava is 
not a Solr dependency in its own right \u2014 it is shaded 
inside\n`hadoop-client-runtime` (reported by scan [...]
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1236,11 +1236,11 @@
       "analysis": {
         "state": "not_affected",
         "justification": "code_not_reachable",
-        "detail": "CVE-2024-26308 (CVSS 6.7) is a denial-of-service issue in 
Apache Commons Compress: unpacking a\nmalformed **Pack200** 
(`.pack`/`.pack.gz`) stream can allocate excessive memory and 
throw\n`OutOfMemoryError` (affects 1.21 through 1.25.0, fixed in 1.26.0). It is 
reachable only when an\napplication uses Commons Compress to unpack an 
attacker-supplied Pack200 archive.\n\nSolr is **not affected**. Solr never 
unpacks Pack200 archives \u2014 Pack200 (a legacy JAR-compression\n [...]
+        "detail": "CVE-2024-26308 (CVSS 6.7) is a denial-of-service issue in 
Apache Commons Compress: unpacking a\nmalformed **Pack200** 
(`.pack`/`.pack.gz`) stream can allocate excessive memory and 
throw\n`OutOfMemoryError` (affects 1.21 through 1.25.0, fixed in 1.26.0). It is 
reachable only when an\napplication uses Commons Compress to unpack an 
attacker-supplied Pack200 archive.\n\nSolr is **not affected**. Solr never 
unpacks Pack200 archives \u2014 Pack200 (a legacy JAR-compression\n [...]
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1253,11 +1253,11 @@
       "analysis": {
         "state": "not_affected",
         "justification": "code_not_reachable",
-        "detail": "CVE-2024-29131 and CVE-2024-29133 are denial-of-service 
issues (StackOverflowError) in Apache Commons\nConfiguration's list-delimiter 
handling \u2014 `AbstractListDelimiterHandler.flattenIterator(...)` 
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a 
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0, 
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses 
`commons-configuration2` only through its optional Hadoop\nint [...]
+        "detail": "CVE-2024-29131 and CVE-2024-29133 are denial-of-service 
issues (StackOverflowError) in Apache Commons\nConfiguration's list-delimiter 
handling \u2014 `AbstractListDelimiterHandler.flattenIterator(...)` 
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a 
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0, 
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses 
`commons-configuration2` only through its optional Hadoop\nint [...]
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1270,11 +1270,11 @@
       "analysis": {
         "state": "not_affected",
         "justification": "code_not_reachable",
-        "detail": "CVE-2024-29131 and CVE-2024-29133 are denial-of-service 
issues (StackOverflowError) in Apache Commons\nConfiguration's list-delimiter 
handling \u2014 `AbstractListDelimiterHandler.flattenIterator(...)` 
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a 
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0, 
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses 
`commons-configuration2` only through its optional Hadoop\nint [...]
+        "detail": "CVE-2024-29131 and CVE-2024-29133 are denial-of-service 
issues (StackOverflowError) in Apache Commons\nConfiguration's list-delimiter 
handling \u2014 `AbstractListDelimiterHandler.flattenIterator(...)` 
and\n`ListDelimiterHandler.flatten(Object, int)` respectively \u2014 when a 
configuration contains a cyclic\nreference (both affect 2.0 through 2.10.0, 
fixed in 2.10.1).\n\nSolr is **not affected**. Solr uses 
`commons-configuration2` only through its optional Hadoop\nint [...]
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1291,7 +1291,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1308,7 +1308,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1325,7 +1325,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1342,7 +1342,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1359,7 +1359,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1376,7 +1376,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1396,7 +1396,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1416,7 +1416,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1436,7 +1436,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1453,7 +1453,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1473,7 +1473,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1490,7 +1490,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1507,7 +1507,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1524,7 +1524,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1541,7 +1541,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1558,7 +1558,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1575,7 +1575,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1592,7 +1592,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1609,7 +1609,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1626,7 +1626,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1643,7 +1643,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1660,7 +1660,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1677,7 +1677,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1694,7 +1694,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1711,7 +1711,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1728,7 +1728,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1745,7 +1745,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1762,7 +1762,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1779,7 +1779,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1796,7 +1796,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1813,7 +1813,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1830,7 +1830,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1847,7 +1847,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1864,7 +1864,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1877,11 +1877,11 @@
       "analysis": {
         "state": "not_affected",
         "justification": "code_not_reachable",
-        "detail": "CVE-2024-47561 (critical) is an arbitrary-code-execution 
issue in the Apache Avro Java SDK: parsing\nan attacker-controlled Avro 
**schema** can instantiate arbitrary classes (affects avro < 
1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when 
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require 
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is 
**not affected**:\n\n* **Solr does not use Apache Avro.** There [...]
+        "detail": "CVE-2024-47561 (critical) is an arbitrary-code-execution 
issue in the Apache Avro Java SDK: parsing\nan attacker-controlled Avro 
**schema** can instantiate arbitrary classes (affects avro < 
1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when 
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require 
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is 
**not affected**:\n\n* **Solr does not use Apache Avro.** There [...]
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1894,11 +1894,11 @@
       "analysis": {
         "state": "not_affected",
         "justification": "code_not_reachable",
-        "detail": "CVE-2024-47561 (critical) is an arbitrary-code-execution 
issue in the Apache Avro Java SDK: parsing\nan attacker-controlled Avro 
**schema** can instantiate arbitrary classes (affects avro < 
1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when 
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require 
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is 
**not affected**:\n\n* **Solr does not use Apache Avro.** There [...]
+        "detail": "CVE-2024-47561 (critical) is an arbitrary-code-execution 
issue in the Apache Avro Java SDK: parsing\nan attacker-controlled Avro 
**schema** can instantiate arbitrary classes (affects avro < 
1.11.4).\nCVE-2023-39410 is a memory-exhaustion / DoS issue when 
**deserializing untrusted Avro data** (affects\navro < 1.11.3). Both require 
the application to feed attacker-controlled Avro input to the SDK.\n\nSolr is 
**not affected**:\n\n* **Solr does not use Apache Avro.** There [...]
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1915,7 +1915,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1932,7 +1932,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1949,7 +1949,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1966,7 +1966,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -1983,7 +1983,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2000,7 +2000,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2017,7 +2017,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2034,7 +2034,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2051,7 +2051,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2068,7 +2068,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2085,7 +2085,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2102,7 +2102,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2119,7 +2119,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2136,7 +2136,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2153,7 +2153,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2170,7 +2170,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2187,7 +2187,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2204,7 +2204,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2221,7 +2221,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2238,7 +2238,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2255,7 +2255,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2272,7 +2272,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2289,7 +2289,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2306,7 +2306,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2323,7 +2323,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2340,7 +2340,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2357,7 +2357,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2374,7 +2374,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2391,7 +2391,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2408,7 +2408,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2425,7 +2425,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     },
@@ -2442,7 +2442,7 @@
       },
       "affects": [
         {
-          "ref": "898a163f-dc2c-5144-8163-289c017c5a85"
+          "ref": "133498f9-7f34-5c49-95e5-f5ed0ca792e6"
         }
       ]
     }
diff --git a/output/vex.html b/output/vex.html
index 7fb0698ab..fe68553e6 100644
--- a/output/vex.html
+++ b/output/vex.html
@@ -663,10 +663,14 @@ avro &lt; 1.11.3). Both require the application to feed 
attacker-controlled Avro
   own internal machinery, driven by administrator-supplied configuration, not 
by untrusted request
   input.</li>
 </ul>
-<p>The affected range covers the 9.x line, where the optional Hadoop modules 
transitively carry Avro
-1.9.2; Solr's own code path never invokes it. A scanner surfaces this as 
<code>[email protected]</code> because Avro is
-shaded inside <code>hadoop-client-runtime-3.4.0.jar</code> in the 
<code>hdfs</code> module (this is the form reported by
-SOLR-17900); it is the same non-reachable Hadoop transitive either way.</p>
+<p>The affected range covers Solr 9.0.0 – 9.10.1, where the optional Hadoop 
modules transitively carry a
+vulnerable Avro (1.7.7 in <code>hadoop-client-runtime</code> 3.3.2 – 3.3.6, 
then 1.9.2 in 3.4.0 – 3.4.1); Solr's
+own code path never invokes it. A scanner surfaces this as 
<code>[email protected]</code> because Avro is shaded inside
+<code>hadoop-client-runtime</code> in the <code>hdfs</code> module (the form 
reported by SOLR-17900). Unlike the other
+Hadoop-shaded CVEs from SOLR-17900, Avro stayed vulnerable all the way through 
9.10.1: Solr 9.11
+(branch_9x) is the first fixed release, having upgraded to Hadoop 3.4.3, whose 
<code>hadoop-client-runtime</code>
+shades Avro 1.11.4 (past both the 1.11.3 and 1.11.4 fixes). Solr 10.x ships no 
<code>hadoop-client-runtime</code>.
+Either way it is the same non-reachable Hadoop transitive.</p>
 
                 <h4>References</h4>
                 <ul>
@@ -2303,7 +2307,7 @@ extraction out of Solr (the recommended architecture) or 
replace the bundled
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 9.0.0-9.10.1</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 9.0.0-9.9.0</p>
                     </div>
                 </header>
 
@@ -2319,7 +2323,10 @@ integration — both the standalone copy in the 
<code>hadoop-auth</code> module
 path feeds attacker-controlled configuration to Commons Configuration, so the 
recursive list-delimiter
 parser cannot be driven by an adversary. This matches the existing assessment 
of the other Commons
 Configuration CVEs (CVE-2022-33980, CVE-2026-45205). The affected range spans 
the releases whose
-Hadoop modules carry an affected commons-configuration2 (Solr 9.0.0 – 
9.10.1).</p>
+Hadoop modules carry an affected commons-configuration2 — Solr 9.0.0 – 9.9.0 
(<code>hadoop-client-runtime</code>
+3.3.2 – 3.4.0 shades commons-configuration2 ≤ 2.8.0; the standalone 
<code>hadoop-auth</code> copy was already
+≥ 2.10.1, at 2.11.0, by 9.7.0). Solr 9.10.0 upgraded to Hadoop 3.4.1, whose 
<code>hadoop-client-runtime</code>
+shades the fixed commons-configuration2 2.10.1, so 9.10.x onward is not 
affected.</p>
 
                 <h4>References</h4>
                 <ul>
@@ -2339,7 +2346,7 @@ Hadoop modules carry an affected commons-configuration2 
(Solr 9.0.0 – 9.10.1).
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 9.0.0-9.10.1</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 9.0.0-9.9.0</p>
                     </div>
                 </header>
 
@@ -2354,7 +2361,10 @@ format) is not part of any Solr request path. The 
affected <code>commons-compres
 module; Solr's HDFS-client usage does not feed untrusted Pack200 input to it, 
and Solr's own use of
 Commons Compress elsewhere does not invoke the Pack200 unpacker. The 
vulnerable code path is therefore
 not reached. The affected range spans the releases whose <code>hdfs</code> 
module bundles an affected shaded
-commons-compress (Solr 9.0.0 – 9.10.1); Solr 10.x ships no 
<code>hadoop-client-runtime</code>.</p>
+commons-compress — Solr 9.0.0 – 9.9.0 (<code>hadoop-client-runtime</code> 
3.3.2 – 3.4.0, shading commons-compress
+≤ 1.24.0; the standalone copy in the <code>extraction</code> module was 
already ≥ 1.26.0 by 9.7.0). Solr 9.10.0
+upgraded to Hadoop 3.4.1, whose <code>hadoop-client-runtime</code> shades the 
fixed commons-compress 1.26.1, and
+Solr 10.x ships no <code>hadoop-client-runtime</code>, so neither is 
affected.</p>
 
                 <h4>References</h4>
                 <ul>
@@ -2374,7 +2384,7 @@ commons-compress (Solr 9.0.0 – 9.10.1); Solr 10.x ships 
no <code>hadoop-client
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 9.0.0-9.10.1</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 9.0.0-9.9.0</p>
                     </div>
                 </header>
 
@@ -2389,7 +2399,9 @@ where Hadoop may use it for name resolution. Solr uses 
the HDFS module only as a
 connects to operator-configured HDFS NameNode/DataNode hosts, not 
attacker-controlled names, and it
 does not rely on dnsjava's DNSSEC validation to make any security decision. 
The vulnerable resolver
 path is therefore not reached. The affected range spans the releases whose 
<code>hdfs</code> module bundles an
-affected shaded dnsjava (Solr 9.0.0 – 9.10.1); Solr 10.x ships no 
<code>hadoop-client-runtime</code>.</p>
+affected shaded dnsjava — Solr 9.0.0 – 9.9.0 
(<code>hadoop-client-runtime</code> 3.3.2 – 3.4.0, shading dnsjava
+≤ 3.4.0). Solr 9.10.0 upgraded to Hadoop 3.4.1, whose 
<code>hadoop-client-runtime</code> shades the fixed dnsjava
+3.6.1, and Solr 10.x ships no <code>hadoop-client-runtime</code>, so neither 
is affected.</p>
 
                 <h4>References</h4>
                 <ul>
@@ -2448,7 +2460,7 @@ extraction in a separate Tika service, or replace 
<code>modules/extraction/lib/a
                             <strong>Status:</strong>
                             <span class="cdx-not-affected">not_affected</span>
                         </p>
-                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 9.0.0-9.10.1</p>
+                            <p class="subheader"><strong>Affected Solr 
versions:</strong> 9.0.0-9.9.0</p>
                     </div>
                 </header>
 
@@ -2462,8 +2474,10 @@ application parses attacker-supplied JOSE/JWT input with 
Nimbus.</p>
 scanner flags (<code>[email protected]</code>) is shaded inside 
<code>hadoop-client-runtime</code> in the optional
 <code>hdfs</code> module and is only used by Hadoop's own internal auth 
machinery — Solr never routes an
 untrusted, externally-supplied JOSE object to it. The vulnerable parser is 
therefore not reached. The
-affected range spans the releases whose <code>hdfs</code> module bundles the 
affected shaded Nimbus (Solr
-9.0.0 – 9.10.1); Solr 10.x ships no <code>hadoop-client-runtime</code>.</p>
+affected range spans the releases whose <code>hdfs</code> module bundles an 
affected shaded Nimbus — Solr
+9.0.0 – 9.9.0 (<code>hadoop-client-runtime</code> 3.3.2 – 3.4.0, shading 
Nimbus ≤ 9.31). Solr 9.10.0 upgraded to
+Hadoop 3.4.1, whose <code>hadoop-client-runtime</code> shades the fixed Nimbus 
9.37.2, and Solr 10.x ships no
+<code>hadoop-client-runtime</code>, so neither is affected.</p>
 
                 <h4>References</h4>
                 <ul>

Reply via email to