solr: XML resource consumption attack via update handler
Published Sep 10, 2019
7.5
HIGHCVSS 3.1
EPSS 8.55%
Description
Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.
Affected products
-
- Version 1.3.0 to 1.4.1StatusaffectedConstraints-
- Version 3.1.0 to 3.6.2StatusaffectedConstraints-
- Version 4.0.0 to 4.10.4StatusaffectedConstraints-
- Version
No data.
Red Hat JBoss Data Virtualization 6
solr-core
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
solr-core
Out of support scope
Red Hat JBoss Fuse 6
solr-core
Not affected
Red Hat JBoss Fuse Service Works 6
solr-core
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Data Virtualization 6 | solr-core | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | solr-core | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | solr-core | Not affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | solr-core | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.55% (0.08547) | 94.90th | v5 (v2026.06.15) |
| Sep 11, 2026 | 8.55% (0.08547) | 94.73th | v5 (v2026.06.15) |
| Jun 15, 2026 | 7.51% (0.07505) | 93.69th | v5 (v2026.06.15) |
| Mar 1, 2026 | 32.77% (0.32768) | 96.80th | v4 (v2025.03.14) |
| Nov 21, 2025 | 28.20% (0.28199) | 96.29th | v4 (v2025.03.14) |
| Nov 18, 2025 | 40.83% (0.40834) | 97.21th | v4 (v2025.03.14) |
| Jun 19, 2025 | 28.20% (0.28199) | 96.23th | v4 (v2025.03.14) |
| Mar 30, 2025 | 32.77% (0.32768) | 96.50th | v4 (v2025.03.14) |
| Mar 29, 2025 | 56.96% (0.56962) | 97.30th | v4 (v2025.03.14) |
| Mar 24, 2025 | 32.77% (0.32768) | 96.48th | v4 (v2025.03.14) |
| Mar 23, 2025 | 42.53% (0.42532) | 97.06th | v4 (v2025.03.14) |
| Mar 19, 2025 | 32.77% (0.32768) | 96.33th | v4 (v2025.03.14) |
| Mar 17, 2025 | 36.89% (0.36888) | 96.79th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.23% (0.00234) | 62.30th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.23% (0.00234) | 61.28th | v3 (v2023.03.01) |
| Aug 17, 2023 | 0.32% (0.00318) | 66.58th | v3 (v2023.03.01) |
| Aug 1, 2023 | 0.28% (0.00278) | 64.04th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.33% (0.00327) | 66.20th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.03% (0.03032) | 83.64th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.03% (0.03032) | 81.96th | v2 (v2022.01.01) |
| Feb 4, 2022 | 24.93% (0.24927) | 95.37th | v2 (v2022.01.01) |
| Feb 3, 2022 | 25.52% (0.25522) | 95.59th | v1 |
| Jan 6, 2022 | 25.52% (0.25522) | 95.53th | v1 |
| Sep 1, 2021 | 7.09% (0.07095) | 91.31th | v1 |
| Apr 14, 2021 | 7.09% (0.07095) | 0.00th | v1 |
References (24)
- http://mail-archives.us.apache.org/mod_mbox/www-announce/201909.mbox/%3CCAECwjAXU4%3DkAo5DeUJw7Kvk67sgCmajAN7LGZQNjbjZ8gv%3DBdw%40mail.gmail.com%3E mailing-listx_refsource_MLISTBroken LinkMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2019/09/10/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-12401 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1789513 Issue Tracking
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-12401-XML%20Bomb-Apache%20Solr x_refsource_MISCExploitThird Party Advisory
- https://github.com/advisories/GHSA-jq2w-w7v2-69q5 Advisory
- https://issues.apache.org/jira/browse/SOLR-13750
- https://lists.apache.org/thread.html/048ae6e4f84a88e8856f766320b48ad91f9fca2c6f621aa2c40088fe%40%3Cdev.lucene.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/048ae6e4f84a88e8856f766320b48ad91f9fca2c6f621aa2c40088fe@%3Cdev.lucene.apache.org%3E
- https://lists.apache.org/thread.html/0ec231c5ed8d242890e21806d25fdd47f80cc47cac278d2fc1c9c579%40%3Cdev.lucene.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/0ec231c5ed8d242890e21806d25fdd47f80cc47cac278d2fc1c9c579@%3Cdev.lucene.apache.org%3E
- https://lists.apache.org/thread.html/1c92300643f48f13bc59b15e3f886ba62bae1798c7d4c2e5c1ece09b%40%3Cannounce.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/1c92300643f48f13bc59b15e3f886ba62bae1798c7d4c2e5c1ece09b@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/521d10a19bfb590f86dff41820ccfb11e92281f233a12c882650931e%40%3Cdev.lucene.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/521d10a19bfb590f86dff41820ccfb11e92281f233a12c882650931e@%3Cdev.lucene.apache.org%3E
- https://lists.apache.org/thread.html/60a924662ead9aeea74e8ea128d9ca935f8de925aa71b15ab2787d6a%40%3Csolr-user.lucene.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/60a924662ead9aeea74e8ea128d9ca935f8de925aa71b15ab2787d6a@%3Csolr-user.lucene.apache.org%3E
- https://lists.apache.org/thread.html/7ab5e95a1a0b4f35ffe53f1eb0cb74b4348b49d41b72ac155b843fa2%40%3Cgeneral.lucene.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/7ab5e95a1a0b4f35ffe53f1eb0cb74b4348b49d41b72ac155b843fa2@%3Cgeneral.lucene.apache.org%3E
- https://lists.apache.org/thread.html/db8eaca456d03c00a66cbe37548978318d424b9997e3fd7f5c65dffe%40%3Cdev.lucene.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/db8eaca456d03c00a66cbe37548978318d424b9997e3fd7f5c65dffe@%3Cdev.lucene.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2019-12401
- https://security.netapp.com/advisory/ntap-20190926-0002/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-12401
Change history (0)
No recorded changes yet.