PT-2025-49099 · Apache +1 · Apache Tika +4
Published
2025-12-04
·
Updated
2025-12-08
·
CVE-2025-66516
CVSS v4.0
10
10
Critical
| Base vector | Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Apache Tika versions 1.13 through 3.2.1
Apache Tika tika-pdf-module versions 2.0.0 through 3.2.1
Apache Tika tika-parsers versions 1.13 through 1.28.5
Description
Apache Tika is affected by a critical XML External Entity (XXE) injection flaw. This issue, exploitable via crafted XFA files within PDF documents, allows attackers to potentially read server files or execute remote code. The vulnerability resides in the
tika-core component, impacting the tika-parser-pdf-module and, in 1.x releases, the tika-parsers module. Exploitation occurs when Tika processes PDFs containing XFA data without restricting external XML entities. Approximately 200 hosts in the Russian network segment are estimated to be vulnerable, with a potential impact on 95% of those systems. The vulnerability allows reading arbitrary files from the host or initiating Server-Side Request Forgery (SSRF) attacks. The affected components include the XML parser within tika-core.Recommendations
Update Apache Tika to version 3.2.2, ensuring that
tika-core is also updated.
If an immediate update is not possible, temporarily disable or restrict the processing of XFA-PDF files, and implement validation and filtering of incoming documents.
Isolate Tika processes using sandboxing, restrict file system access, and prohibit outgoing requests.
Verify dependencies in applications that utilize Tika, as it may be included transitively through search modules or ECM platforms.
Audit Tika logs and logs from all services where automatic PDF analysis is performed.Fix
RCE
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
CVE-2025-66516
GHSA-F58C-GQ56-VJJF
Affected Products
Apache Tika
Debian
Tika-Core
Tika-Parsers
Tika-Pdf-Module
References · 63
- https://security-tracker.debian.org/tracker/CVE-2025-66516 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-66516 · Security Note
- https://cve.org/CVERecord?id=CVE-2025-54988 · Security Note
- https://lists.apache.org/thread/s5x3k93nhbkqzztp1olxotoyjpdlps9k · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66516 · Security Note
- https://osv.dev/vulnerability/GHSA-f58c-gq56-vjjf · Vendor Advisory
- https://github.com/apache/tika⭐ 3445 🔗 886 · Note
- https://twitter.com/threatcluster/status/1997863771893600456 · Twitter Post
- https://twitter.com/pigram86/status/1996991297295352242 · Twitter Post
- https://t.me/CVEtracker/38845 · Telegram Post
- https://twitter.com/buzz_sec/status/1996989347694788617 · Twitter Post
- https://twitter.com/TheCyberSecHub/status/1996989522849214974 · Twitter Post
- https://packages.debian.org/src:tika · Note
- https://t.me/purp_sec/1324 · Telegram Post
- https://reddit.com/r/CVEWatch/comments/1pgftjk/top_10_trending_cves_07122025 · Reddit Post