CVE-2025-66516: Maximum-Severity Vulnerability in Apache Tika Could Lead to XML External Entity Injection Attack
ID: a8569569-6066-5fc6-a499-94442385d43c
STIX ID: report--a8569569-6066-5fc6-a499-94442385d43c
Feed Name: SOC Prime Blog
Threat Score
**Executive Summary:** CVE-2025-66516 is a maximum-severity (CVSS 10.0) XML External Entity (XXE) vulnerability affecting multiple Apache Tika components (tika-core, tika-pdf-module, tika-parsers) that can be triggered by embedding a malicious XFA file inside a PDF, potentially exposing server files and enabling remote code execution; users should urgently update affected modules (tika-core >= 3.2.2 and corresponding parsers) to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
