Hello,

I've spent a bit of time reading through the discussions related to Tika,
specifically the plan to remove the embedded version from Solr 10 onward.

We have an engineer already looking into this, but I figured a community
post wouldn't hurt...

For those of us currently stuck on 9.8.x who do not make use of Tika
functionality in any way but need to upgrade or remove Tika as part of
vulnerability management, is there a documented or official way to
disable/remove the Tika packages from the installation?

The main goal here is to stop getting hits on CVE-2025-54988 /
CVE-2025-66516 due to the version included with our installation.

Thank you!

Reply via email to