epugh commented on PR #245: URL: https://github.com/apache/solr-site/pull/245#issuecomment-6004304016
## CVEs resolved between 9.10.1 and 9.11.0 **40 individual CVE/GHSA identifiers**, across **36 VEX entries**, affect Solr 9.10.1 but no longer apply to 9.11.0: | Cause | Count | CVEs | |---|---|---| | **Netty** bumped to 4.2.15.Final | 17 | CVE-2026-41417, -42577, -42578, -42580, -42581, -42583, -42584, -42585, -42587, -44249, -45416, -45536, -47244, -48043, -50010, -50020, -50560 | | **jackson-databind** bumped to 2.22.2 | 5 | CVE-2026-54514, -54515, -59888, -59889, GHSA-mhm7-754m-9p8w | | **Log4j** bumped to 2.26.1 | 5 | CVE-2026-34477, -34478, -34479, -34480, -34481 | | **Tika 1.x→3.x jump dropped the dependency** entirely | 6 | CVE-2012-0881 (xercesImpl), CVE-2016-6809 + CVE-2018-1335/-1338/-1339 (vorbis-java-tika), CVE-2024-21742 (mime4j) | | **OpenNLP** bumped to 1.9.5 (+ Solr's own allowlist) | 3 | CVE-2026-40682, -42027, -42440 | | **Hadoop** bumped to 3.4.3 (Avro shaded inside it) | 2 | CVE-2024-47561, CVE-2023-39410 | | **commons-beanutils** bumped to 1.11.0 | 1 | CVE-2025-48734 | | **poi-ooxml** bumped to 5.5.1 | 1 | CVE-2025-31672 | Most of these were already `not_affected`/unreachable in 9.10.1 too (Solr never hit the vulnerable code path) — the dependency bump formally closes the gap rather than fixing an active exploit. The two genuinely `exploitable`-until-now entries are OpenNLP's CVE-2026-42027 (arbitrary class instantiation, CVSS 9.8) and CVE-2026-40682 (XXE, CVSS 9.1) — those are the ones where 9.11.0 closes a real, reachable hole rather than just tidying up a classpath concern. Two CVEs are *not* on this list despite initially looking like candidates, because their underlying dependency is unchanged in 9.11.0 (Bouncy Castle's CVE-2023-33201 family, and jetty-http's CVE-2024-6763) — both ranges were extended to 9.11.0 rather than capped at 9.10.1. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
