Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.0

CVE-2026-47898: Apache Lucene.Net: Malicious XML Data Can Cause Harm

CVE-2026-47898 CVE-2026-47898
Summary

Apache Lucene.Net's PatternParser has a weakness that can allow attackers to inject malicious XML data. This could potentially cause harm to your system. To fix this, update to version 4.8.0-beta00018 of the Lucene.Net.Analysis.Common library.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
apache software foundation apache lucene.net < 4.8.0-beta00018
apache lucene.net 4.8.0
cpe:2.3:a:apache:lucene.net:4.8.0:beta00005:*:*:*:*:*:*
Original title
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta...
Original description
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).

This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018.

Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
Vulnerability type
CWE-611 XML External Entity (XXE)
Published: 3 Jul 2026 · Updated: 23 Jul 2026 · First seen: 3 Jul 2026