epugh commented on PR #245:
URL: https://github.com/apache/solr-site/pull/245#issuecomment-6004304016

   ## CVEs resolved between 9.10.1 and 9.11.0
   
   **40 individual CVE/GHSA identifiers**, across **36 VEX entries**, affect 
Solr 9.10.1 but no longer apply to 9.11.0:
   
   | Cause | Count | CVEs |
   |---|---|---|
   | **Netty** bumped to 4.2.15.Final | 17 | CVE-2026-41417, -42577, -42578, 
-42580, -42581, -42583, -42584, -42585, -42587, -44249, -45416, -45536, -47244, 
-48043, -50010, -50020, -50560 |
   | **jackson-databind** bumped to 2.22.2 | 5 | CVE-2026-54514, -54515, 
-59888, -59889, GHSA-mhm7-754m-9p8w |
   | **Log4j** bumped to 2.26.1 | 5 | CVE-2026-34477, -34478, -34479, -34480, 
-34481 |
   | **Tika 1.x→3.x jump dropped the dependency** entirely | 6 | CVE-2012-0881 
(xercesImpl), CVE-2016-6809 + CVE-2018-1335/-1338/-1339 (vorbis-java-tika), 
CVE-2024-21742 (mime4j) |
   | **OpenNLP** bumped to 1.9.5 (+ Solr's own allowlist) | 3 | CVE-2026-40682, 
-42027, -42440 |
   | **Hadoop** bumped to 3.4.3 (Avro shaded inside it) | 2 | CVE-2024-47561, 
CVE-2023-39410 |
   | **commons-beanutils** bumped to 1.11.0 | 1 | CVE-2025-48734 |
   | **poi-ooxml** bumped to 5.5.1 | 1 | CVE-2025-31672 |
   
   Most of these were already `not_affected`/unreachable in 9.10.1 too (Solr 
never hit the vulnerable code path) — the dependency bump formally closes the 
gap rather than fixing an active exploit. The two genuinely 
`exploitable`-until-now entries are OpenNLP's CVE-2026-42027 (arbitrary class 
instantiation, CVSS 9.8) and CVE-2026-40682 (XXE, CVSS 9.1) — those are the 
ones where 9.11.0 closes a real, reachable hole rather than just tidying up a 
classpath concern.
   
   Two CVEs are *not* on this list despite initially looking like candidates, 
because their underlying dependency is unchanged in 9.11.0 (Bouncy Castle's 
CVE-2023-33201 family, and jetty-http's CVE-2024-6763) — both ranges were 
extended to 9.11.0 rather than capped at 9.10.1.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to