Repository navigation
Security release 11.2.8
Security release for TYPO3 10.4 ELTS. This is the first public release of this line since
11.2.3 — 11.2.4 through 11.2.7 were only ever published on the private ELTS mirror and stay
unpublished; there is no patched 11.2.7 or earlier to move to, upgrade straight to 11.2.8.
This is the last planned release on this branch — EXT:solr no longer supports TYPO3 10.4 ELTS
after this release.
Highlights
- CVE-2026-56092 — Page indexer no longer poisons the rootline cache (
d17636ae3) - CVE-2026-56093 — Detail view enforces site and access restrictions (
c766b3283) - CVE-2026-56094 —
additionalFilterscan no longer preempt thesiteHashfilter (5d1dc6dd0) - CVE-2026-56096 — User-controlled Solr query syntax is escaped; closes an FVH
FieldExistsQueryHTTP 500 oracle (d0fb087ae) - CVE-2026-56095 (multi-value cObjs JSON transport) does not apply to this branch — the regression it fixes was never introduced here (
05305306e) - [FEATURE] The Docker image now ships a
HEALTHCHECK(0e7eaec75) - [BUGFIX] Ignore an emptied filter section in the plugin FlexForm by @dkd-kaehm in #4790
Full details: Documentation/Releases/solr-release-11-2.rst
Contributors
How to Get Involved
There are many ways to get involved with Apache Solr for TYPO3:
- Submit bug reports and feature requests on GitHub
- Ask or help or answer questions in our Slack channel
- Provide patches through pull requests or review and comment on existing pull requests
- Go to www.typo3-solr.com or call dkd to sponsor the ongoing development of Apache Solr for TYPO3
Support us by becoming an EB partner:
https://shop.dkd.de/Produkte/Apache-Solr-fuer-TYPO3/
or call:
+49 (0)69 - 2475218 0