Security Advisory
CVE-2026-75595 — io.netty:netty-handler
|
Severity |
Critical |
|
Affected Component |
Solr (bundled with FileCloud) |
|
Status |
Fix available — manual remediation required |
|
Versions affected |
FileCloud versions 23.232 through 23.262.2.34016 |
|
Version fixed |
FileCloud version 23.263 and later |
Summary
A critical vulnerability, CVE-2026-75595, has been identified in io.netty:netty-handler (versions prior to 4.2.17.Final), which is bundled as a dependency within the Solr search component shipped with FileCloud. This library is used to support OpenTelemetry instrumentation and Zookeeper/SolrCloud networking functions within Solr.
FileCloud's product security team has verified that these components are not required for core FileCloud functionality — including setup, indexing, reindexing, and search (with and without OCR). Customers are advised to remove the affected JAR files and restart Solr as described below.
Affected Versions / Scope
-
Solr version: 9.10.1 (as bundled with FileCloud)
-
Affected package: io.netty:netty-handler 4.2.6.Final and related dependent JARs
Impact
The vulnerable Netty components are used by:
-
OpenTelemetry (observability/tracing module)
-
Zookeeper / SolrCloud networking
They are not used by core Solr indexing, search, or FileCloud document processing paths, so removal does not affect normal FileCloud operation.
What you should do to fix this vulnerability
FileCloud Server admins:
If you are performing a new installation of FileCloud, this issue will be fixed for you.
If you are not performing a new installation of FileCloud, do the following to fix this issue:
FileCloud Online Admins
This issue will be fixed for you when the latest version of FileCloud is released on October 10-11, 2026.
If you have any questions about this advisory, please contact FileCloud support.