CVE 10 CRITICAL

Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected_CVE-2025-66516

10 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF.

This CVE covers the same vulnerability as inΒ CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways.

First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable.

Second, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the "org.apache.tika:tika-parsers" module.

AI Analysis

Critical XML External Entity (XXE) vulnerability in Apache Tika's tika-core, tika-pdf-module, and tika-parsers modules via a crafted XFA file inside a PDF, allowing XML External Entity injection attacks.

Basic Information

ID CVE-2025-66516
Source apache
Published Dec 4, 2025 at 16:17

Affected Product

Vendor Apache Software Foundation
Product Apache Tika core
Version 1.13
Affected Versions Apache Software Foundation Apache Tika core 1.13
Apache Software Foundation Apache Tika parsers 1.13
Apache Software Foundation Apache Tika PDF parser module 2.0.0

CWE Classification

AI Assessment

AI Score 10 / 10
AI Severity Critical
Vendor Apache Software Foundation
Product Apache Tika
Version 1.13-3.2.1, 2.0.0-3.2.1, 1.13-1.28.5

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.