Repository navigation
Release 14.0.0
We are happy to release the first stable release of EXT:solr 14.0.0 for TYPO3 14 LTS — and at the same time a security release, carrying the forward-port of the five vulnerabilities fixed in 13.1.4.
📖 Full release notes: Releases 14.0
⚠️ Security
Reported through the TYPO3 Security Team. Installations running 14.0.0-RC1 or earlier should update.
- CVE-2026-56092 — the
fe_group/extendToSubpages-forging listener is removed - CVE-2026-56093 — the detail view enforces site and access restrictions
- CVE-2026-56094 —
tx_solr[additionalFilters]can no longer preempt thesiteHashor access filter - CVE-2026-56095 — multi-value cObjs switch to JSON transport (breaking for third-party content objects that rely on
serialize()) - CVE-2026-56096 — user-controlled Solr query syntax is escaped and field selectors are whitelisted
Requirements
| TYPO3 | 14.3+ |
| PHP | 8.2+ |
| Apache Solr | 10.0.0 |
| Configset | ext_solr_14_0_0 |
| EXT:tika | 14.0.0+ |
| EXT:solrfal | 14.0.0+ |
Apache Solr 10 is required — the configset and the managed-resources API were adapted for Jetty 12. Please read the breaking changes before upgrading; a schema update and a full re-index are needed.
Highlights
Collected from the whole 14.0.0-alpha1 → 14.0.0 cycle.
TYPO3 14 and the platform
- !!! Full TYPO3 14 LTS compatibility, on stable TYPO3 14.3.x
- !!! Apache Solr 10 / Lucene 10 required — deprecated trie-based dynamic fields removed,
ExtractingRequestHandlerdropped in favour of EXT:tika 14+ - !!!
solarium/solarium7.0.0 — removesAbstractQueryBuilder::removeOperator()andremoveAlternativeQuery()without alternatives - All language files migrated to XLIFF 2.0, event listeners moved to the
#[AsEventListener]attribute - Scheduler tasks implement
getTaskParameters()/setTaskParameters(), so TYPO3 core'sSchedulerDatabaseStorageMigrationcan migrate them — re-run that migration if your EXT:solr tasks were not migrated before this release - EXT:install is an optional dependency, static analysis moved to PHPStan 2
Indexing
- !!! Unified sub-request indexing pipeline — no HTTP round-trips to itself any more, and significantly faster
- !!! The
indexerIndex Queue setting and the Index Queue Indexer are retired; indexing runs throughIndexingServiceand the PSR-14 indexing events - !!!
RecordInsertedEventintroduced,isNewRecorddropped fromRecordUpdatedEvent - !!! A failed Index Queue item records why it failed, and Index Queue initialization stops at nested site roots
- New
BeforeIndexingSubRequestIsPreparedEventlets listeners reset state that must not leak between sub-requests - Site hash finalized by site identifier — dedicated
domainandtypo3Contextschema fields replace the ad-hoc_stringSfields - No
c:0variant and no content leakage onfe_group-restricted pages - State no longer leaks between indexing sub-requests: language Context aspect, page title, Context aspects, page cache and the backend web context
Search and frontend
- !!! jQuery is gone — search, suggest, facet and range controllers rewritten in vanilla JavaScript
- Site sets registered for all TypoScript templates
- Spellchecking keeps correctly-spelled terms when offering corrections
- Suggest fixes: preventable submission, mobile/offcanvas dropdown positioning,
routeEnhancersupport, several search forms per page - Facet URL encoding fixed for spaces with
urlParameterStyle=assoc - Long Solr GET requests are converted to POST; the
PostBigRequestlistener became opt-in - ASCII folding is applied before stemming in all language schemas
- Backend module icons in the TYPO3 14 style
Removed API
- !!!
DataUpdateHandler::removeFromIndexAndQueueWhenItemInQueue(),PageIndexer::isPageIndexable(),QueueInitializationServiceAwareInterfaceand the related Queue API - !!! The legacy PageIndexer system, replaced by
IndexingInstructions - !!! The site hash strategy flag
- !!! The trailing space in the
searchResultClassNameandsearchResultSetClassNameconfiguration keys - !!!
Highlighting::getUseFastVectorHighlighter()
What's Changed since 14.0.0-RC1
- [CLEANUP] Remove unneeded dependency on fluid-styled-content by @dmitryd in #4729
- Update docs on
query.queryFieldsandquery.sortByby @kitzberger in #4726 - [BUGFIX] PHPStan issues 2026.08.12 by @dkd-kaehm in #4731
- [TASK] Make EXT:install an optional dependency by @wazum in #4676
- [BUGFIX] Convert long Solr GET requests to POST on PSR-14 dispatcher by @wazum in #4631
- [DOCS] Update links to Apache Solr Reference Guide by @tillhoerner in #4736
- [BUGFIX] Prevent PHP warning when building the access rootline for uncollected Index Queue pages by @konradmichalik in #4728
- [BUGFIX] Restore Context aspects after indexing sub-request by @hdj-typoconsult in #4733
- [TASK] Remove obsolete "addRootLineFields" setting by @tillhoerner in #4735
- [BUGFIX] fix autosuggestion initialization for multiple search forms on one page by @dkd-kaehm in #4747
- [BUGFIX] Apply ASCII folding before stemming in all language schemas by @tgaertner in #4741
- [BUGFIX] Prevent undefined array key warning in SettingsPreviewOnPlug… by @mschwemer in #4686
- [SECURITY] Fix CVE-2026-56096 — close FVH FieldExistsQuery HTTP 500 oracle by @dkd-kaehm in #4751
- [TASK] fixes for EXT:solrfal sync by @dkd-kaehm in #4738
- [TASK] Guard against silently losing a test case by @dkd-kaehm in #4754
- [TASK] Index pages through the production pipeline in integration tests by @dkd-kaehm in #4755
- [TASK] Retire the hand-built IndexingInstructions from the integration tests by @dkd-kaehm in #4756
- [TASK] Retire the indexer Index Queue setting by @dkd-kaehm in #4758
- [!!!][BUGFIX] Report why an Index Queue item failed, and stop queueing foreign sites' pages by @dkd-kaehm in #4759
- [!!!][TASK] Remove the Index Queue Indexer, and assert record indexing against the pipeline by @dkd-kaehm in #4760
- [SECURITY] Forward-port the 13.1.4 security release to TYPO3 14 (CVE-2026-56092 … 56096) by @dkd-kaehm in #4763
New Contributors
- @wazum made their first contribution in #4676
- @hdj-typoconsult made their first contribution in #4733
- @tgaertner made their first contribution in #4741
Full Changelog: 14.0.0-RC1...14.0.0
Contributors
Like always this release would not have been possible without the help from our awesome community. Here are the contributors to this release (patches, comments, bug reports, reviews, … in alphabetical order):
@amirarends, @un3us, @danilovq, @BastiLu, @beardcoder, @bmack, @pi-phi, @daylightsoftware, @dmitryd, @dkd-lehnebach, @garfieldius, @hdj-typoconsult, @helhum, @hnadler, @jschlier, @konradmichalik, @mschwemer, @dkd-friedrich, @mikelwohlschlegel, @dkd-hauser, @dkd-dobberkau, @kitzberger, @dkd-kaehm, @saschanowak, @sfroemkenjw, @tillhoerner, @tgaertner, @guelzow, @wazum
Also a big thank you to our partners who have already concluded one of our new development participation packages such as Apache Solr EB for TYPO3 14 LTS (Feature):
- CS2 AG
- digit.ly
- fixpunkt werbeagentur gmbh
- in2code GmbH
- L.N. Schaffrath DigitalMedien GmbH
- LOUIS INTERNET GmbH
- queo GmbH
- toco3 GmbH & Co. KG
- Umweltbundesamt GmbH
- Universität für Musik und darstellende Kunst Wien
- Universität Regensburg
How to Get Involved
There are many ways to get involved with Apache Solr for TYPO3:
- Submit bug reports and feature requests on GitHub
- Ask or help or answer questions in our Slack channel
- Provide patches through pull requests or review and comment on existing pull requests
- Go to www.typo3-solr.com or call dkd to sponsor the ongoing development of Apache Solr for TYPO3
Support us by becoming an EB partner:
https://shop.dkd.de/Produkte/Apache-Solr-fuer-TYPO3/
or call:
+49 (0)69 - 2475218 0