Security Advisories (4)
CVE-2026-61484 (2026-08-05)

Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-61483 (2026-08-05)

Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-61485 (2026-08-05)

Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-61486 (2026-08-05)

Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

NAME

Lucy::Index::LexiconReader - Read Lexicon data.

SYNOPSIS

my $lex_reader = $seg_reader->obtain("Lucy::Index::LexiconReader");
my $lexicon    = $lex_reader->lexicon( field => 'title' );

DESCRIPTION

LexiconReader reads term dictionary information.

ABSTRACT METHODS

lexicon

my $lexicon = $lexicon_reader->lexicon(
    field => $field,  # required
    term  => $term,   # default: undef
);

Return a new Lexicon for the given field. Will return undef if either the field is not indexed, or if no documents contain a value for the field.

  • field - Field name.

  • term - Pre-locate the Lexicon to this term.

doc_freq

my $int = $lexicon_reader->doc_freq(
    field => $field,  # required
    term  => $term,   # required
);

Return the number of documents where the specified term is present.

METHODS

aggregator

my $result = $lexicon_reader->aggregator(
    readers => $readers,  # required
    offsets => $offsets,  # required
);

Return a LexiconReader which merges the output of other LexiconReaders.

  • readers - An array of LexiconReaders.

  • offsets - Doc id start offsets for each reader.

INHERITANCE

Lucy::Index::LexiconReader isa Lucy::Index::DataReader isa Clownfish::Obj.