Package
solr-9-full
Component
tika-parsers
Latest update
8.4
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
Upstream's advisory for this issue (https://solr.apache.org/security-news.html#cve-2025-66516-apache-solr-extraction-module-vulnerable-to-xxe-attacks-via-xfa-content-in-pdfs) lists Solr 6.2.0 through 9.10.0 as affected. Solr 9.10.1 ships SOLR-17888, whose extraction handler forces extractAcroFormContent off unless an operator explicitly enables it, so Tika's XFA extraction path is never invoked in the shipped configuration.
Status