// OSSeva Blog
SecurityApache Solr Vulnerabilities by Version: CVEs for Solr 7, 8, 9 and 10
The short answer
Two Solr release lines get security fixes from the Apache Solr project. Solr 10 is the current major line, and its latest release is 10.0.0 from 3 March 2026. Solr 9.10.x is the previous major line and may still get the odd critical fix; its latest release, 9.10.1 from 20 January 2026, is described on the downloads page as the last release in the 9.x series. Every version below 9.10 is end of life. Solr 8 reached end of life on 25 October 2024 with 8.11.4 as its final release, and Solr 7 on 11 May 2022 with 7.7.3. Since Solr 8 ended, the Solr PMC has published five CVEs that list 8.x versions as affected. None of them has an 8.x fix.
Solr release lines and support status
| Line | Status | Latest release | Upstream security fixes |
|---|---|---|---|
| 10.x | Current major line | 10.0.0, 3 March 2026 | Yes |
| 9.x | Previous major line; versions below 9.10 are end of life | 9.10.1, 20 January 2026 | 9.10.x only, for critical issues |
| 8.x | End of life 25 October 2024 | 8.11.4, 24 September 2024 | No |
| 7.x | End of life 11 May 2022 | 7.7.3 | No |
For dates on every line back to Solr 1.4, see the Apache Solr end of life tracker.
Solr CVEs published since Solr 8 reached end of life
CVSS is NVD's own score where NVD has scored the record. Most recent Solr records carry only the CVSS 3.1 score that CISA-ADP added, and those are marked CISA-ADP. The rating column is the Solr PMC's own.
| CVE | Issue | CVSS | Solr rating | Affected | Fixed in | Solr 8 and 7 |
|---|---|---|---|---|---|---|
| CVE-2026-22022 | Some predefined permission rules in the RuleBasedAuthorizationPlugin can be bypassed | 8.2 (CISA-ADP) | Moderate | 5.3.0 to 9.10.0 | 9.10.1 | No fix |
| CVE-2026-22444 | The create core API does not fully enforce allowPaths, and can leak NTLM hashes on Windows | 7.1 (CISA-ADP) | Moderate | 8.6 to 9.10.0 | 9.10.1 | No fix for 8.6 and later; 7 is not affected |
| CVE-2025-66516 | XXE in the extraction module, through a Tika flaw in PDF XFA parsing | 9.8 (NVD, on the Tika record) | High | 6.2.0 to 9.10.0, when the extraction module is used | Configuration change; Solr says 9.10.1 and later apply it by default | No fix |
| CVE-2025-24814 | Core creation can swap trusted configset files for untrusted ones | 5.5 (NVD) | Moderate | All versions through 9.7 | 9.8.0 | No fix |
| CVE-2024-52012 | Configset upload on Windows allows writes outside the target directory (zip slip) | 5.4 (CISA-ADP) | Moderate | 6.6 to 9.7.0 | 9.8.0 | No fix |
CVE-2025-66516 hits older lines harder. On Solr 6.2 to 8.x a crafted PDF can read any file the Solr process can read, such as /etc/passwd or application secrets. On 9.x the Java Security Manager, on by default, limits it to Solr's own directories. The fix is a parseContext.xml file that turns off AcroForm extraction, and it works on any version with the extraction module.
In May 2026 the PMC also published an advisory without a CVE. The JWT Authentication Plugin's blockUnknown setting has always defaulted to false in code, although the Reference Guide has said true since Solr 9.0, so some clusters that meant to block anonymous requests have been accepting them. It affects 9.0.0 to 9.10.1 and 10.0.0. Setting blockUnknown to true in security.json is enough, and no upgrade is needed.
Older CVEs that still matter on Solr 8 and 7
These were fixed before Solr 8 ended, so a current 8.11.4 install has the fix. Solr 7 stopped at 7.7.3 and has none of them.
| CVE | Issue | CVSS | Affected | Fixed in | Solr 7 |
|---|---|---|---|---|---|
| CVE-2024-45216 | Authentication bypass in PKIAuthenticationPlugin with a fake URL path ending | 9.8 (CISA-ADP) | 5.3.0 before 8.11.4; 9.0.0 before 9.7.0 | 8.11.4, 9.7.0 | No fix |
| CVE-2024-45217 | Configsets created by a backup restore are trusted implicitly | 8.1 (CISA-ADP) | 6.6.0 before 8.11.4; 9.0.0 before 9.7.0 | 8.11.4, 9.7.0 | No fix |
| CVE-2023-50386 | Backup and restore APIs let executables into configsets | 8.8 (NVD) | 6.0.0 to 8.11.2; 9.0.0 before 9.4.1 | 8.11.3, 9.4.1 | No fix |
| CVE-2021-44228 | Log4Shell in the bundled Log4j 2 library | 10.0 (NVD) | 7.4.0 to 7.7.3; 8.0.0 to 8.11.0 | 8.11.1 | No release; mitigation only |
| CVE-2021-44548 | DataImportHandler accepts Windows UNC paths and makes SMB calls | 9.8 (NVD) | All versions before 8.11.1, Windows only | 8.11.1 | No fix |
| CVE-2021-27905 | SSRF through the replication handler's leaderUrl parameter | 9.8 (NVD) | 7.0.0 to 7.7.3; 8.0.0 to 8.8.1 | 8.8.2 | No fix |
| CVE-2021-29943 | ConfigurableInternodeAuthHadoopPlugin forwards requests with server credentials | 9.1 (NVD) | 7.0.0 to 7.7.3; 8.0.0 to 8.8.1 | 8.8.2 | No fix |
| CVE-2020-13957 | Checks on unauthenticated configset uploads can be circumvented | 9.8 (NVD) | 6.6.0 to 6.6.6; 7.0.0 to 7.7.3; 8.0.0 to 8.6.2 | 8.6.3 | No fix |
| CVE-2019-17558 | Remote code execution through the VelocityResponseWriter | 7.5 (NVD) | 5.0.0 to 8.3.1 | 8.4.0 | NVD's range for 7.x ends before 7.7.3 |
For Log4Shell on Solr 7.4 and later, the Solr advisory accepts setting log4j2.formatMsgNoLookups=true in solr.in.sh or replacing the Log4j jar. It also says Solr is not exposed to the follow-up CVE-2021-45046 and CVE-2021-45105. Solr releases before 7.4 ship Log4j 1.2.17 instead.
Solr 10
Solr 10.0.0 shipped on 3 March 2026. It needs Java 21 and runs on Lucene 10.3 and Jetty 12. None of the January 2026 CVEs reach it, because their ranges end at 9.10.0. The JWT blockUnknown advisory does apply, and the PMC has said the default will change in 10.1. Moving from 9 to 10 is a major version change, so plan a reindex and a relevance check.
Solr 9
Solr 9.10.1 fixed CVE-2026-22022 and CVE-2026-22444, and it is the only 9.x release the project still treats as supported. A cluster on 9.7.x is missing the 9.8.0 fixes for CVE-2025-24814 and CVE-2024-52012 as well. The downloads page describes 9.10.1 as the last 9.x release, so 9.x estates should treat 10 as the next stop. See the Solr 8 to 9 upgrade guide for what changes between majors.
Solr 8
Solr 8 reached end of life on 25 October 2024, when the Lucene and Solr PMCs said no further 8.x releases would ship. Its final release, 8.11.4 on 24 September 2024, fixed CVE-2024-45216 and CVE-2024-45217. All five CVEs in the first table list 8.x as affected and have fixes on 9.x only. See Apache Solr 8 end of life.
Solr 7
Solr 7 reached end of life on 11 May 2022, the day Solr 9.0 was released. Its last release is 7.7.3. It never got the Log4Shell fix, the 8.8.2 fixes for CVE-2021-27905 and CVE-2021-29943, or the 8.11.x fixes for configset and authentication bypass bugs. It is also affected by four of the five CVEs published since Solr 8 ended. See Apache Solr 7 end of life.
Solr remote code execution CVEs
Most code execution paths in Solr run through configsets. A trusted configset, one uploaded by an authenticated user, can load code with lib directives, Velocity templates and custom plugins. Many Solr CVEs come down to an untrusted configset being treated as trusted:
- CVE-2019-17558 (7.5). Velocity templates supplied as parameters or in a configset run code on the server. Fixed in 8.4.0.
- CVE-2020-13957 (9.8). Combining UPLOAD and CREATE actions gets dangerous features past the checks on unauthenticated configset uploads. Fixed in 8.6.3.
- CVE-2023-50386 (8.8). Jar and class files uploaded in a configset can be written by a backup into a directory on Solr's classpath, where any configset can use them. Fixed in 8.11.3 and 9.4.1.
- CVE-2024-45217 (8.1) and CVE-2025-24814 (5.5). Restored configsets, and core creation in standalone mode, both produce trusted configsets without an authenticated upload. Fixed in 8.11.4 and 9.7.0, and in 9.8.0, respectively.
Each of these needs Solr's admin APIs to be reachable without authentication, or reachable by users who should not have them. That is why the Solr advisories keep recommending authentication and authorization, and say that no Solr API is designed to be exposed to untrusted parties. SolrCloud clusters also depend on a ZooKeeper ensemble that is often older than Solr itself; see ZooKeeper for Solr.
What to do on each line
- 10. Stay on the latest release, and set blockUnknown explicitly if you use JWT authentication.
- 9. Move to 9.10.1 now and plan the move to 10.
- 8 and 7. Upgrade to 9.10.1 or 10, which means a reindex, or take patched builds from a supplier that backports fixes. Until then, turn on authentication and authorization, restrict the configset and core admin APIs to administrators, and apply the parseContext.xml fix if you index PDFs with the extraction module.
Where OSSeva fits
OSSeva backports Solr security fixes to 6.x, 7.x and 8.x, including fixes in the bundled Lucene, Jetty and ZooKeeper client. The builds keep the Lucene index format, schema handling and analysers of the line you run, so they drop onto the existing data directory with no reindex. They are available now on the Patch, Assure and Operate tiers. Assure adds a handler exposure audit, a SolrCloud and ZooKeeper security review and a reindex plan for 9.x or 10.x, and Operate adds 24/7 cluster monitoring with a 15-minute P1 response and named Solr engineers. See Apache Solr extended support.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.