Critical Apache Tika Vulnerability: CVE-2025-66516 Enables XXE Injection
ID: 89b0f7cd-f703-573a-9ffd-7dfb279839e9
STIX ID: report--89b0f7cd-f703-573a-9ffd-7dfb279839e9
Feed Name: Abstract Security Blog
CVE-2025-66516 is a critical XXE vulnerability in Apache Tika (CVSS 10.0) affecting tika-core, tika-parser-pdf-module, and tika-parsers that can be exploited by processing a crafted PDF containing XFA content to perform arbitrary file reads, SSRF, or cause DoS; organizations must upgrade tika-core to 3.2.2 (and tika-parsers to 2.0.0 for 1.x users), audit transitive dependencies, and apply mitigations such as disabling PDF parsing, sandboxing, and network restrictions while monitoring for the provided IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
