Back to blog

// OSSeva Blog

Security

Apache Solr Vulnerabilities by Version: CVEs for Solr 7, 8, 9 and 10

Randall McClure9 min read

The short answer

Two Solr release lines get security fixes from the Apache Solr project. Solr 10 is the current major line, and its latest release is 10.0.0 from 3 March 2026. Solr 9.10.x is the previous major line and may still get the odd critical fix; its latest release, 9.10.1 from 20 January 2026, is described on the downloads page as the last release in the 9.x series. Every version below 9.10 is end of life. Solr 8 reached end of life on 25 October 2024 with 8.11.4 as its final release, and Solr 7 on 11 May 2022 with 7.7.3. Since Solr 8 ended, the Solr PMC has published five CVEs that list 8.x versions as affected. None of them has an 8.x fix.

Solr release lines and support status

LineStatusLatest releaseUpstream security fixes
10.xCurrent major line10.0.0, 3 March 2026Yes
9.xPrevious major line; versions below 9.10 are end of life9.10.1, 20 January 20269.10.x only, for critical issues
8.xEnd of life 25 October 20248.11.4, 24 September 2024No
7.xEnd of life 11 May 20227.7.3No

For dates on every line back to Solr 1.4, see the Apache Solr end of life tracker.

Solr CVEs published since Solr 8 reached end of life

CVSS is NVD's own score where NVD has scored the record. Most recent Solr records carry only the CVSS 3.1 score that CISA-ADP added, and those are marked CISA-ADP. The rating column is the Solr PMC's own.

CVEIssueCVSSSolr ratingAffectedFixed inSolr 8 and 7
CVE-2026-22022Some predefined permission rules in the RuleBasedAuthorizationPlugin can be bypassed8.2 (CISA-ADP)Moderate5.3.0 to 9.10.09.10.1No fix
CVE-2026-22444The create core API does not fully enforce allowPaths, and can leak NTLM hashes on Windows7.1 (CISA-ADP)Moderate8.6 to 9.10.09.10.1No fix for 8.6 and later; 7 is not affected
CVE-2025-66516XXE in the extraction module, through a Tika flaw in PDF XFA parsing9.8 (NVD, on the Tika record)High6.2.0 to 9.10.0, when the extraction module is usedConfiguration change; Solr says 9.10.1 and later apply it by defaultNo fix
CVE-2025-24814Core creation can swap trusted configset files for untrusted ones5.5 (NVD)ModerateAll versions through 9.79.8.0No fix
CVE-2024-52012Configset upload on Windows allows writes outside the target directory (zip slip)5.4 (CISA-ADP)Moderate6.6 to 9.7.09.8.0No fix

CVE-2025-66516 hits older lines harder. On Solr 6.2 to 8.x a crafted PDF can read any file the Solr process can read, such as /etc/passwd or application secrets. On 9.x the Java Security Manager, on by default, limits it to Solr's own directories. The fix is a parseContext.xml file that turns off AcroForm extraction, and it works on any version with the extraction module.

In May 2026 the PMC also published an advisory without a CVE. The JWT Authentication Plugin's blockUnknown setting has always defaulted to false in code, although the Reference Guide has said true since Solr 9.0, so some clusters that meant to block anonymous requests have been accepting them. It affects 9.0.0 to 9.10.1 and 10.0.0. Setting blockUnknown to true in security.json is enough, and no upgrade is needed.

Older CVEs that still matter on Solr 8 and 7

These were fixed before Solr 8 ended, so a current 8.11.4 install has the fix. Solr 7 stopped at 7.7.3 and has none of them.

CVEIssueCVSSAffectedFixed inSolr 7
CVE-2024-45216Authentication bypass in PKIAuthenticationPlugin with a fake URL path ending9.8 (CISA-ADP)5.3.0 before 8.11.4; 9.0.0 before 9.7.08.11.4, 9.7.0No fix
CVE-2024-45217Configsets created by a backup restore are trusted implicitly8.1 (CISA-ADP)6.6.0 before 8.11.4; 9.0.0 before 9.7.08.11.4, 9.7.0No fix
CVE-2023-50386Backup and restore APIs let executables into configsets8.8 (NVD)6.0.0 to 8.11.2; 9.0.0 before 9.4.18.11.3, 9.4.1No fix
CVE-2021-44228Log4Shell in the bundled Log4j 2 library10.0 (NVD)7.4.0 to 7.7.3; 8.0.0 to 8.11.08.11.1No release; mitigation only
CVE-2021-44548DataImportHandler accepts Windows UNC paths and makes SMB calls9.8 (NVD)All versions before 8.11.1, Windows only8.11.1No fix
CVE-2021-27905SSRF through the replication handler's leaderUrl parameter9.8 (NVD)7.0.0 to 7.7.3; 8.0.0 to 8.8.18.8.2No fix
CVE-2021-29943ConfigurableInternodeAuthHadoopPlugin forwards requests with server credentials9.1 (NVD)7.0.0 to 7.7.3; 8.0.0 to 8.8.18.8.2No fix
CVE-2020-13957Checks on unauthenticated configset uploads can be circumvented9.8 (NVD)6.6.0 to 6.6.6; 7.0.0 to 7.7.3; 8.0.0 to 8.6.28.6.3No fix
CVE-2019-17558Remote code execution through the VelocityResponseWriter7.5 (NVD)5.0.0 to 8.3.18.4.0NVD's range for 7.x ends before 7.7.3

For Log4Shell on Solr 7.4 and later, the Solr advisory accepts setting log4j2.formatMsgNoLookups=true in solr.in.sh or replacing the Log4j jar. It also says Solr is not exposed to the follow-up CVE-2021-45046 and CVE-2021-45105. Solr releases before 7.4 ship Log4j 1.2.17 instead.

Solr 10

Solr 10.0.0 shipped on 3 March 2026. It needs Java 21 and runs on Lucene 10.3 and Jetty 12. None of the January 2026 CVEs reach it, because their ranges end at 9.10.0. The JWT blockUnknown advisory does apply, and the PMC has said the default will change in 10.1. Moving from 9 to 10 is a major version change, so plan a reindex and a relevance check.

Solr 9

Solr 9.10.1 fixed CVE-2026-22022 and CVE-2026-22444, and it is the only 9.x release the project still treats as supported. A cluster on 9.7.x is missing the 9.8.0 fixes for CVE-2025-24814 and CVE-2024-52012 as well. The downloads page describes 9.10.1 as the last 9.x release, so 9.x estates should treat 10 as the next stop. See the Solr 8 to 9 upgrade guide for what changes between majors.

Solr 8

Solr 8 reached end of life on 25 October 2024, when the Lucene and Solr PMCs said no further 8.x releases would ship. Its final release, 8.11.4 on 24 September 2024, fixed CVE-2024-45216 and CVE-2024-45217. All five CVEs in the first table list 8.x as affected and have fixes on 9.x only. See Apache Solr 8 end of life.

Solr 7

Solr 7 reached end of life on 11 May 2022, the day Solr 9.0 was released. Its last release is 7.7.3. It never got the Log4Shell fix, the 8.8.2 fixes for CVE-2021-27905 and CVE-2021-29943, or the 8.11.x fixes for configset and authentication bypass bugs. It is also affected by four of the five CVEs published since Solr 8 ended. See Apache Solr 7 end of life.

Solr remote code execution CVEs

Most code execution paths in Solr run through configsets. A trusted configset, one uploaded by an authenticated user, can load code with lib directives, Velocity templates and custom plugins. Many Solr CVEs come down to an untrusted configset being treated as trusted:

  • CVE-2019-17558 (7.5). Velocity templates supplied as parameters or in a configset run code on the server. Fixed in 8.4.0.
  • CVE-2020-13957 (9.8). Combining UPLOAD and CREATE actions gets dangerous features past the checks on unauthenticated configset uploads. Fixed in 8.6.3.
  • CVE-2023-50386 (8.8). Jar and class files uploaded in a configset can be written by a backup into a directory on Solr's classpath, where any configset can use them. Fixed in 8.11.3 and 9.4.1.
  • CVE-2024-45217 (8.1) and CVE-2025-24814 (5.5). Restored configsets, and core creation in standalone mode, both produce trusted configsets without an authenticated upload. Fixed in 8.11.4 and 9.7.0, and in 9.8.0, respectively.

Each of these needs Solr's admin APIs to be reachable without authentication, or reachable by users who should not have them. That is why the Solr advisories keep recommending authentication and authorization, and say that no Solr API is designed to be exposed to untrusted parties. SolrCloud clusters also depend on a ZooKeeper ensemble that is often older than Solr itself; see ZooKeeper for Solr.

What to do on each line

  • 10. Stay on the latest release, and set blockUnknown explicitly if you use JWT authentication.
  • 9. Move to 9.10.1 now and plan the move to 10.
  • 8 and 7. Upgrade to 9.10.1 or 10, which means a reindex, or take patched builds from a supplier that backports fixes. Until then, turn on authentication and authorization, restrict the configset and core admin APIs to administrators, and apply the parseContext.xml fix if you index PDFs with the extraction module.

Where OSSeva fits

OSSeva backports Solr security fixes to 6.x, 7.x and 8.x, including fixes in the bundled Lucene, Jetty and ZooKeeper client. The builds keep the Lucene index format, schema handling and analysers of the line you run, so they drop onto the existing data directory with no reindex. They are available now on the Patch, Assure and Operate tiers. Assure adds a handler exposure audit, a SolrCloud and ZooKeeper security review and a reindex plan for 9.x or 10.x, and Operate adds 24/7 cluster monitoring with a 15-minute P1 response and named Solr engineers. See Apache Solr extended support.

Tags

Apache SolrCVESolr 8Solr 7End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.