Apache Solr 6.2.0 < 9.10.1 Extraction Module XML External Entity

critical Web App Scanning Plugin ID 115557

Synopsis

Apache Solr 6.2.0 < 9.10.1 Extraction Module XML External Entity

Description

Apache Solr versions 6.2.0 through 9.10.0 are affected by an XML External Entity (XXE) vulnerability in the extraction module (SolrCell) caused by a flaw in Apache Tika's handling of XFA content in PDF documents. Deployments using the default 'local' extraction backend and accepting untrusted PDF uploads can be abused to read arbitrary files (limited to Solr directories by the Security Manager on 9.x), cause a denial of service or perform limited network requests. Solr instances not using the extraction module are not affected.

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update to Apache Solr version 9.10.1 or latest. Alternatively, configure a parseContext.xml disabling 'extractAcroFormContent' and reference it from the /update/extract handler.

See Also

https://issues.apache.org/jira/browse/SOLR-17888

https://solr.apache.org/security-news.html#cve-2025-66516-apache-solr-extraction-module-vulnerable-to-xxe-attacks-via-xfa-content-in-pdfs

Plugin Details

Severity: Critical

ID: 115557

Type: Version Based

Published: 10/2/2026

Updated: 10/2/2026

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.59

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-66516

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2025-66516

CVSS v4

Risk Factor: Critical

Base Score: 10

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CVSS Score Source: CVE-2025-66516

Vulnerability Information

CPE: cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/3/2025

Reference Information

CVE: CVE-2025-66516