OSSEVA FOR APACHE SOLR

Solr 8 ended 25 October 2024. Your index did not.

Search clusters are rebuilt, not upgraded — schema, analysers, query parsers and relevance tuning are all version-coupled. That is why so many production estates are still on Solr 8 nearly a year after upstream stopped patching it, and on Solr 7 four years after.

Why now

Solr 8 has been unpatched since 25 October 2024

Apache Solr 8 reached end of life on 25 October 2024, with 8.11.4 as its final release. Solr 7 ended on 11 May 2022. Upstream maintains the 9.x line and has now shipped Solr 10, released 3 March 2026. Nothing is backported below 9.

Solr is frequently the most exposed service in the estate

Solr has a long history of remote code execution advisories reached through the config API, the VelocityResponseWriter, the DataImportHandler and the streaming expression handlers. Many deployments were stood up behind an assumption of network isolation that no longer matches how the application calls them. Deserialization and SSRF classes hit this component hard.

Upgrading Solr means re-validating relevance, not just swapping a binary

Lucene index formats change between majors, analysers are deprecated, and query parser behaviour shifts in ways that move result ordering. A Solr upgrade is a reindex plus a relevance regression cycle plus sign-off from whoever owns search quality. Extended support is what buys the time to do that properly.

Versions covered

All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.

VersionStatusActive CVEs
6.x(Community EOL 13 Mar 2019 — OSSeva patched)EOLClean
7.x(Community EOL 11 May 2022 — OSSeva patched)EOLClean
8.x(Community EOL 25 Oct 2024 — OSSeva patched)EOLClean
9.x(Upstream maintained)ExtendedClean
10.x(Released 3 Mar 2026)CurrentClean

What you get

Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.

OSSeva Patch

CVE patches for Solr 6, 7 and 8 with the index format unchanged.

  • Security backports for 6.x, 7.x and 8.x — no reindex required
  • Config API, VelocityResponseWriter and DIH advisory coverage
  • Bundled Lucene, Jetty and Zookeeper client patching
  • Docker / tarball / WAR delivery
  • Signed artifacts (GPG)
  • Relevance regression testing
  • 24/7 managed operations
Get started →
Most popular

OSSeva Assure

Patch plus exposure audit and a reindex-aware upgrade plan.

  • Everything in Patch
  • Handler and request-path exposure audit
  • SolrCloud and ZooKeeper ensemble security review
  • Schema and analyser deprecation inventory for 9.x / 10.x
  • SOC 2 / HIPAA attestation package
  • Reindex strategy and relevance regression plan
  • 24/7 managed operations
Get started →

OSSeva Operate

Full MSP: 24/7 cluster monitoring, 15-min SLA, named search engineers.

  • Everything in Assure
  • 24/7 query latency, shard health and replica monitoring
  • 15-minute P1 incident response SLA
  • Named senior Solr / Lucene engineer
  • Index optimisation and segment merge management
  • Upgrade execution with parallel-index cutover
  • Quarterly relevance and capacity reviews
Get started →

All tiers priced per cluster/application — not per core. Contact for pricing →

How it installs

OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.

Check the version and the handlers it exposesbash
# Version, JVM and uptime
curl -s 'http://solr:8983/solr/admin/info/system?wt=json' \
  | jq '.lucene["solr-spec-version"], .jvm.version'

# Anything at 8.x or below receives no upstream security fixes.

# List enabled request handlers — the historical RCE paths live here
curl -s 'http://solr:8983/solr/mycore/config?wt=json' \
  | jq '.config.requestHandler | keys'
Docker — OSSeva Solrbash
# Drop-in replacement, same index format, same schema
docker pull artifacts.osseva.io/solr:8.11.4-osseva-1

docker run -d --name solr \
  -p 8983:8983 \
  -v /var/solr:/var/solr \
  artifacts.osseva.io/solr:8.11.4-osseva-1 \
  solr-foreground

Migrate from Unsupported community Solr 7.x and 8.x

OSSeva ships patched Solr builds on the line you already run, so the Lucene index format, schema and analyser chain stay exactly as they are and no reindex is required to become secure. The upgrade to Solr 9 or 10 is then planned properly, with a parallel index and a relevance regression cycle rather than a rushed cutover.

Pricing model

OSSeva for Apache Solr is priced per cluster — not per node, core, shard or indexed document.

Compliance library

📄SOC 2 compliance evidence package
Request →
📄Sample Audit Narrative
Request →
📄Pen-Test Report Summary
Request →
📄HIPAA Technical Safeguard Matrix
Request →

Frequently asked questions

Which versions of RabbitMQ are past community end-of-life?

RabbitMQ 3.8.x, 3.9.x, 3.10.x, 3.11.x, and 3.12.x have all reached community EOL — meaning no further security patches or CVE fixes are released by the RabbitMQ maintainers for those versions. RabbitMQ 3.13.x reached EOL in late 2024. OSSeva delivers backported CVE patches for 3.11 through 3.13.

Which PostgreSQL versions are no longer receiving community security patches?

PostgreSQL 9.6 through 13 have all reached community EOL. PostgreSQL 11 reached EOL November 2023, PostgreSQL 12 reached EOL November 2024, and PostgreSQL 13 reaches EOL November 2025. OSSeva provides extended security patching for PostgreSQL 11, 12, and 13 for teams that cannot immediately migrate to PG 14 or later.

Is Spring Framework 5.3.x still supported?

Spring Framework 5.3.x reached its community OSS EOL on December 31, 2024. Broadcom's commercial support for Spring 5.3.x is also no longer available under standard terms. OSSeva delivers backported CVE patches for Spring Framework 5.3.x and Spring Boot 2.7.x under our extended lifecycle support program.

Which versions of Apache Kafka are EOL?

Apache Kafka versions 2.x and 3.0 through 3.4 are past their community supported window, meaning no further patch releases. Kafka 3.5 and 3.6 have reached or are approaching EOL. OSSeva supports Kafka 2.8 through 3.5 with backported security patches and compliance documentation.

What happened to Redis licensing? Can I still use Redis for free?

In March 2024, Redis Ltd. changed the Redis license from BSD-3-Clause to the Business Source License (BSL 1.1), which restricts use in competing database products. The Valkey project (a Linux Foundation fork) continues under BSD-3-Clause. OSSeva maintains BSD-licensed, CVE-patched builds of Redis 6.2 and 7.0 for enterprises that need verifiable open-source licensing alongside security coverage.

Is Node.js 18 still receiving security patches?

Node.js 18 (LTS 'Hydrogen') reached its end-of-life date in April 2025 and no longer receives security releases from the Node.js project. OSSeva delivers CVE patches for Node.js 18 for enterprise teams that have not yet migrated to Node.js 20 or 22.

Is Apache Tomcat 8.5 still supported?

Apache Tomcat 8.5 reached its community EOL in March 2024. OSSeva provides extended security patching for Tomcat 8.5.x for teams running Java EE 7 workloads that cannot immediately migrate to Tomcat 9.0 or 10.1.

What .NET versions does OSSeva support?

.NET 6 reached Microsoft end-of-support in November 2024. .NET 7 reached EOL in May 2024. OSSeva delivers CVE patches for .NET 6 and .NET 7 for teams that have not yet migrated to .NET 8 (LTS, supported through November 2026).

Ready to get Apache Solr patched and supported?

Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.