Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.goobi.viewer/viewer-core
  4. ›
  5. CVE-2026-45083

CVE-2026-45083: Goobi viewer - Core: Unauthenticated Solr Streaming Expression Proxy

May 13, 2026 (updated June 8, 2026)

The Goobi viewer REST endpoint POST /api/v1/index/stream accepted an arbitrary Solr streaming expression from unauthenticated network clients and forwarded it to the backend Solr server without restriction. An attacker could read the complete Solr index and, in default Solr deployments, also modify or delete indexed records.

The API endpoint has now been removed.

References

  • github.com/advisories/GHSA-2rgp-f66f-4499
  • github.com/intranda/goobi-viewer-core/commit/326980f24ce1e7cfabf658dd5f615934ca68ebbd
  • github.com/intranda/goobi-viewer-core/commit/6bfb1cbd4250b0b347e84a80f38e8bf46acac705
  • github.com/intranda/goobi-viewer-core/releases/tag/v26.04.1
  • github.com/intranda/goobi-viewer-core/security/advisories/GHSA-2rgp-f66f-4499
  • nvd.nist.gov/vuln/detail/CVE-2026-45083

Code Behaviors & Features

Detect and mitigate CVE-2026-45083 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 4.8.0 up to 26.4.0

Solution

Unfortunately, there is no solution available yet.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-306: Missing Authentication for Critical Function

Source file

maven/io.goobi.viewer/viewer-core/CVE-2026-45083.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:23:03 +0000.