logo

500+ Apache Tika Toolkit Instances Vulnerable to Critical XXE Attack Exposed Online

ID: 72b61877-277c-5d64-980d-aea7754f3670

STIX ID: report--72b61877-277c-5d64-980d-aea7754f3670

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Executive Summary:** Apache disclosed a critical XXE vulnerability (CVE-2025-66516, CVSS 10.0) in tika-core 1.13.0–3.2.1 that can be exploited via a crafted XFA inside a PDF to enable data exfiltration, SSRF, or denial-of-service; Censys found ~565 internet-exposed Tika Server instances and vendors advise upgrading tika-core to 3.2.2+ and updating related parser modules, noting no public PoC or reported active exploitation at disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.