Apache Issues Max-Severity Tika CVE After Patch Miss
ID: 4d415c5a-ba79-52ab-b49b-39de85ba9340
STIX ID: report--4d415c5a-ba79-52ab-b49b-39de85ba9340
Feed Name: Dark Reading
The Apache Software Foundation reissued CVE-2025-66516 (CVSS 10) to correct and expand an earlier XXE vulnerability (CVE-2025-54988) in Apache Tika: the underlying flaw is in tika-core and affects Tika Core and Parsers from 1.13 through 3.2.1 (including PDF modules). Organizations that upgraded only parser modules remain vulnerable; ASF recommends upgrading tika-core to 3.2.2 or later to remediate risks including data disclosure, denial-of-service, and unauthorized connections via crafted XFA files in PDFs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
