#apache-tika

[ follow ]
Information security
fromInfoWorld
5 days ago

Apache Tika hit by critical vulnerability thought to be patched months ago

Apache Tika tika-core 1.13–3.2.1, tika-parsers 1.13–1.28.5, and legacy parsers 1.13–1.28.5 are vulnerable to XXE injection.
#cve-2025-66516
fromTechzine Global
5 days ago
Information security

Apache warns of critical vulnerability in Tika toolkit

A critical CVE-2025-66516 vulnerability in tika-core (CVSS 10.0) requires upgrading to tika-core 3.2.2 to fully mitigate exploitation risks.
fromTheregister
6 days ago
Information security

Apache warns of 10.0-rated flaw in Tika metadata toolkit

A critical Apache Tika vulnerability and rising multi‑terabit DDoS attacks are forcing urgent upgrades and massive defensive capacity expansion.
Information security
fromThe Hacker News
1 week ago

Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch

Apache Tika contains a critical XXE vulnerability (CVE-2025-66516) rated 10.0 that enables XML External Entity injection via crafted XFA files in PDFs.
[ Load more ]