Security Advisories (4)
CVE-2026-61484 (2026-08-05)

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-61483 (2026-08-05)

Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-61485 (2026-08-05)

Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-61486 (2026-08-05)

Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

NAME

Lucy::Index::PolyReader - Multi-segment implementation of IndexReader.

SYNOPSIS

my $polyreader = Lucy::Index::IndexReader->open( 
    index => '/path/to/index',
);
my $doc_reader = $polyreader->obtain("Lucy::Index::DocReader");
for my $doc_id ( 1 .. $polyreader->doc_max ) {
    my $doc = $doc_reader->fetch_doc($doc_id);
    print " $doc_id: $doc->{title}\n";
}

DESCRIPTION

PolyReader conflates index data from multiple segments. For instance, if an index contains three segments with 10 documents each, PolyReader’s doc_max() method will return 30.

Some of PolyReader’s DataReader components may be less efficient or complete than the single-segment implementations accessed via SegReader.

METHODS

doc_max

my $int = $poly_reader->doc_max();

Return the maximum number of documents available to the reader, which is also the highest possible internal document id. Documents which have been marked as deleted but not yet purged from the index are included in this count.

doc_count

my $int = $poly_reader->doc_count();

Return the number of documents available to the reader, subtracting any that are marked as deleted.

del_count

my $int = $poly_reader->del_count();

Return the number of documents which have been marked as deleted but not yet purged from the index.

offsets

my $i32_array = $poly_reader->offsets();

Return an array with one entry for each segment, corresponding to segment doc_id start offset.

seg_readers

my $arrayref = $poly_reader->seg_readers();

Return an array of all the SegReaders represented within the IndexReader.

INHERITANCE

Lucy::Index::PolyReader isa Lucy::Index::IndexReader isa Lucy::Index::DataReader isa Clownfish::Obj.