VYPR
High severity7.5NVD Advisory· Published Sep 10, 2019· Updated Jun 17, 2026

CVE-2019-12401

CVE-2019-12401

Description

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.solr:solr-coreMaven
< 5.0.05.0.0

Affected products

3

Patches

Vulnerability mechanics

References

22

News mentions

0

No linked articles in our index yet.