Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
4.0
CVE-2026-47898: Apache Lucene.Net: Malicious XML Data Can Cause Harm
CVE-2026-47898
CVE-2026-47898
Summary
Apache Lucene.Net's PatternParser has a weakness that can allow attackers to inject malicious XML data. This could potentially cause harm to your system. To fix this, update to version 4.8.0-beta00018 of the Lucene.Net.Analysis.Common library.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache lucene.net | < 4.8.0-beta00018 |
| apache | lucene.net |
4.8.0 cpe:2.3:a:apache:lucene.net:4.8.0:beta00005:*:*:*:*:*:* |
Original title
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).
This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta...
Original description
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).
This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018.
Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018.
Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
Vulnerability type
CWE-611
XML External Entity (XXE)
- https://lists.apache.org/thread/7yn9k6sbbsk18yco5y2hszpcf8dst489 vendor-advisory
- http://www.openwall.com/lists/oss-security/2026/07/03/3 Mailing List Third Party Advisory
Published: 3 Jul 2026 · Updated: 23 Jul 2026 · First seen: 3 Jul 2026