logo

CVE-2025-66516: Maximum-Severity Vulnerability in Apache Tika Could Lead to XML External Entity Injection Attack

ID: a8569569-6066-5fc6-a499-94442385d43c

STIX ID: report--a8569569-6066-5fc6-a499-94442385d43c

Feed Name: SOC Prime Blog

Threat Score
75/100

Date Published: 2025-12-08

Date Updated: 2026-04-30

Author: Veronika Telychko

...
...

**Executive Summary:** CVE-2025-66516 is a maximum-severity (CVSS 10.0) XML External Entity (XXE) vulnerability affecting multiple Apache Tika components (tika-core, tika-pdf-module, tika-parsers) that can be triggered by embedding a malicious XFA file inside a PDF, potentially exposing server files and enabling remote code execution; users should urgently update affected modules (tika-core >= 3.2.2 and corresponding parsers) to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.