Security Advisories (4)
CVE-2026-61484 (2026-08-05)

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-61483 (2026-08-05)

Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-61485 (2026-08-05)

Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-61486 (2026-08-05)

Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

NAME

Lucy::Search::LeafQuery - Leaf node in a tree created by QueryParser.

SYNOPSIS

package MyQueryParser;
use base qw( Lucy::Search::QueryParser );

sub expand_leaf {
    my ( $self, $leaf_query ) = @_;
    if ( $leaf_query->get_text =~ /.\*\s*$/ ) {
        return PrefixQuery->new(
            query_string => $leaf_query->get_text,
            field        => $leaf_query->get_field,
        );
    }
    else {
        return $self->SUPER::expand_leaf($leaf_query);
    }
}

DESCRIPTION

LeafQuery objects serve as leaf nodes in the tree structure generated by QueryParser’s tree() method. Ultimately, they must be transformed, typically into either TermQuery or PhraseQuery objects, as attempting to search a LeafQuery causes an error.

CONSTRUCTORS

new

my $leaf_query = Lucy::Search::LeafQuery->new(
    text  => '"three blind mice"',    # required
    field => 'content',               # default: undef
);

Create a new LeafQuery.

  • field - Optional field name.

  • text - Raw query text.

METHODS

get_field

my $string = $leaf_query->get_field();

Accessor for object’s field attribute.

get_text

my $string = $leaf_query->get_text();

Accessor for object’s text attribute.

make_compiler

my $compiler = $leaf_query->make_compiler(
    searcher    => $searcher,     # required
    boost       => $boost,        # required
    subordinate => $subordinate,  # default: false
);

Throws an error.

INHERITANCE

Lucy::Search::LeafQuery isa Lucy::Search::Query isa Clownfish::Obj.