Warning: Critical vulnerability in Apache Tika modules can lead to data exfiltration and internal network reconnaissance, Patch Immediately!
ID: 7179cae0-616c-5e82-b280-34bbd1824fc0
STIX ID: report--7179cae0-616c-5e82-b280-34bbd1824fc0
Feed Name: CCB Advisories Feed
Apache released advisories for critical XML External Entity (XXE) vulnerabilities in Apache Tika (CVE-2025-66516 and CVE-2025-54988) that can be triggered by crafted XFA in PDFs to exfiltrate data, perform SSRF and cause resource exhaustion; CVSS scores reach 10.0 and 8.4 for affected modules, Apache warns some users who updated only parser modules may remain vulnerable, and recommended actions include upgrading tika-core and related packages, disabling the PDF parser if immediate patching is infeasible, deploying WAF rules, and increasing monitoring (no active exploitation reported as of 05 Dec 2025).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
