logo

Apache Issues Max-Severity Tika CVE After Patch Miss

ID: 4d415c5a-ba79-52ab-b49b-39de85ba9340

STIX ID: report--4d415c5a-ba79-52ab-b49b-39de85ba9340

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-12-08

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

The Apache Software Foundation reissued CVE-2025-66516 (CVSS 10) to correct and expand an earlier XXE vulnerability (CVE-2025-54988) in Apache Tika: the underlying flaw is in tika-core and affects Tika Core and Parsers from 1.13 through 3.2.1 (including PDF modules). Organizations that upgraded only parser modules remain vulnerable; ASF recommends upgrading tika-core to 3.2.2 or later to remediate risks including data disclosure, denial-of-service, and unauthorized connections via crafted XFA files in PDFs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.